Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T120719430A0212527531B0EE9B9A52B0D34A7C31ECB4214103A9E93E51FF3DF5EC1A2A4 |
|
CONTENT
ssdeep
|
96:n2ceMTIydgjke4Nbd6lS4I0sbC4bnvKTSQ:TeDYNIlSu8/i/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
94b979e6649909e6 |
|
VISUAL
aHash
|
07071f1f171f7f00 |
|
VISUAL
dHash
|
3f3f7ffee4fcf0f8 |
|
VISUAL
wHash
|
070f0f1f173f3f00 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
3f3f7ffae4fcf8f8,f0f2f3f3f2f0f0f0 |
• Ameaça: Ataque de phishing para roubo de credenciais
• Alvo: Usuários da Microsoft
• Método: Página de login falsa da Microsoft que rouba email e senha
• Exfil: Dados enviados para /landingpages/7ce652d6-3f52-48de-8c1b-8d3be0f7c1e4/B3HlxmPHs95cvNb095b7QJnLxfdPDdOb54Xpmw5pkS8
• Indicadores: Desajuste de domínio (solutionfun.info vs microsoft.com), envio de formulários via JavaScript
• Risco: CRÍTICO - Roubo de credenciais em tempo real
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain