Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18BD1C73161359CB78093D2E0F6E6AB1B71C6835ADB06020052DCA35D0EEBEC6EE711E4 |
|
CONTENT
ssdeep
|
192:oM3hZAHERKms8NQl5mg4E302XEcHLZQaXQj0sK5r51:tHgr8qn4E302UcdQHj0sK5r51 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3334c4c66735959 |
|
VISUAL
aHash
|
00ffffe7e7ffffff |
|
VISUAL
dHash
|
0808324c4c300000 |
|
VISUAL
wHash
|
00af3b23070f0f0f |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
0c28124c0c100000,0000004040400080 |
• Amenaza: Phishing
• Objetivo: Usuarios de Microsoft
• Método: Suplantación de identidad a través de un formulario de inicio de sesión falso
• Exfil: Dirección de correo electrónico
• Indicadores: Discordancia de dominio, ofuscación de JavaScript, formulario que solicita correo electrónico
• Riesgo: Alto
The attacker is using a deceptive login form to steal user credentials. They are using a domain that is unrelated to the brand, and using JavaScript obfuscation.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain