Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1ED311E619416A52B8302B1C6DDB0430E7FC19652D7035A022AFED39DAB8CE89DC234E0 |
|
CONTENT
ssdeep
|
24:hRfynRqgVRTAQ29HJV7io5K6KpWxoiE+iKAaYoAHck+Mbdf1a:TqdVRTAQwHDios6KabRYoAHckzJ1a |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0e6cf993960c666 |
|
VISUAL
aHash
|
ffffe74fcff7ffff |
|
VISUAL
dHash
|
00126d9d9d6d1200 |
|
VISUAL
wHash
|
3030240c8dbdcfcf |
|
VISUAL
colorHash
|
07000010058 |
|
VISUAL
cropResistant
|
00126d9d9d6d1200 |
• Amenaza: Phishing por suplantación
• Objetivo: Usuarios de DocuSign
• Método: Imitando una página de inicio de sesión de DocuSign
• Exfil: Potencialmente robo de credenciales si el usuario procede.
• Indicadores: Enlace de inicio de sesión inusual, barra de progreso.
• Riesgo: ALTO
The attacker likely wants to steal user credentials. Once the user clicks the link, they will be redirected to a fake login form to input credentials. The attacker will then steal the credentials.
Pages with identical visual appearance (based on perceptual hash)
Found 1 other scan for this domain