Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DF2130EA9881622F44A790D5BB49AB7FF6D6C197D6160E4441FC065FA7E2D04ED36100 |
|
CONTENT
ssdeep
|
24:hRfCMZ9lZRN8UjvLsVPOL81SWrdU7dLAvw7Lsp:TT9rzDjv4V884WrdU7d0I7Yp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c8c2333949ee6667 |
|
VISUAL
aHash
|
f87efc7c18080000 |
|
VISUAL
dHash
|
b1f8e5f1f292b2f8 |
|
VISUAL
wHash
|
fcfefc7c78580800 |
|
VISUAL
colorHash
|
1a007000000 |
|
VISUAL
cropResistant
|
686c64e46cd4e672,b1f8e5f1f292b2f8 |
• Amenaza: Robo de credenciales
• Objetivo: Empleados corporativos
• Método: Phishing de OAuth/SSO
• Exfil: Robo de credenciales mediante inicio de sesión falso
• Indicadores: Dominio extremadamente reciente, branding engañoso
• Riesgo: Alto
Uses a fake corporate login interface to trick users into providing their Google/SSO credentials.
Misrepresents itself as a Microsoft SharePoint portal to target corporate users.