Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11B714170A4601062532B0EE9B9E97B0D3467C34ECA4324147EECD2E95FF2EF5EC152A9 |
|
CONTENT
ssdeep
|
96:T2ceMnzIydgjke4Nbd6lS4I0sbCdmbnvwXFiUSQ:veuyYNIlSu82a4XFik |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
94b979e6649909e6 |
|
VISUAL
aHash
|
07071f1f171f7f00 |
|
VISUAL
dHash
|
3f3f7ffee4fcf0f8 |
|
VISUAL
wHash
|
070f0f1f173f3f00 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
3f3f7ffae4fcf8f8,f0f2f3f3f2f0f0f0 |
• Ameaça: Phishing
• Alvo: Usuários do Microsoft
• Método: Imitação e coleta de credenciais
• Exfil: /landingpages/7ce652d6-3f52-48de-8c1b-8d3be0f7c1e4/b3hlxmphs95cvnb095b7qjnlxfdpddob54xpmw5pks8
• Indicadores: Incompatibilidade de domínio, marca Microsoft em domínio não relacionado.
• Risco: ALTO
The attacker attempts to steal the victim's Microsoft login credentials by mimicking the legitimate login page. The user is tricked into entering their username and password on a fake website, and that information is then sent to the attacker.
Pages with identical visual appearance (based on perceptual hash)
Found 10 other scans for this domain