Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DF2130EA9881622F44A790D5BB49AB7FF6D6C197D6160E4441FC065FA7E2D04ED36100 |
|
CONTENT
ssdeep
|
24:hRfCMZ9lZRN8UjvLsVPOL81SWrdU7dLAvw7Lsp:TT9rzDjv4V884WrdU7d0I7Yp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c8c2333949ee6667 |
|
VISUAL
aHash
|
f87efc7c18080000 |
|
VISUAL
dHash
|
b1f8e5f1f292b2f8 |
|
VISUAL
wHash
|
fcfefc7c78580800 |
|
VISUAL
colorHash
|
1a007000000 |
|
VISUAL
cropResistant
|
686c64e46cd4e672,b1f8e5f1f292b2f8 |
• Ameaça: Roubo de credenciais
• Alvo: Funcionários corporativos
• Método: Phishing de OAuth/SSO
• Exfil: Roubo de credenciais via login falso
• Indicadores: Domínio extremamente recente, branding enganoso
• Risco: Alto
Uses a fake corporate login interface to trick users into providing their Google/SSO credentials.
Misrepresents itself as a Microsoft SharePoint portal to target corporate users.