Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11F4132B010646C6B4143C1D9FB83BA02339295CADF628948B6FC8F9D76EBE05C9102B5 |
|
CONTENT
ssdeep
|
24:n/Ccx7pXO/aCOvhraefDhraHWVeP9ENNa9RDOKZzKwN9uiNu0ag4hrtYPp9P4t58:nXddUaTkefDk2eISCcJHNvadUR9P4U |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a5ccda269c8d634d |
|
VISUAL
aHash
|
ffff623a62627eff |
|
VISUAL
dHash
|
8682cad286cecace |
|
VISUAL
wHash
|
7f62222a4a6262ff |
|
VISUAL
colorHash
|
07400600008 |
|
VISUAL
cropResistant
|
8682cad286cecace |
• Amenaza: Phishing de credenciales
• Objetivo: Usuarios de DocuSign
• Método: Suplantación de identidad con formulario de inicio de sesión.
• Exfil: Desconocido, probablemente a una base de datos.
• Indicadores: Discordancia de dominio, formulario de inicio de sesión.
• Riesgo: ALTO
The attacker attempts to steal user credentials by mimicking the DocuSign login process to obtain sensitive information.
Pages with identical visual appearance (based on perceptual hash)