Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T175428233B600CC2A4DAB95CCF5C496895159C389FB310CCAA1B491BF7BC5DF02AA939D |
|
CONTENT
ssdeep
|
192:KcPVpYUGdIj8DBt5eTT5McnthWeNWbIo22yWKBwfMmUU8VCoZV:0Ijo5eTT3olyWKBwfMmUFCoZV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc65676838676598 |
|
VISUAL
aHash
|
c3f7ffd7dfc3e3ff |
|
VISUAL
dHash
|
062e0ebeb00e4e00 |
|
VISUAL
wHash
|
81c3c3c3cf81c1fe |
|
VISUAL
colorHash
|
070010100c0 |
|
VISUAL
cropResistant
|
062e0ebeb00e4e00,2529222323526462,3adc3d97c9641a33 |
• Ameaça: Phishing
• Alvo: Usuários do Juno
• Método: Impersonificação da página de login
• Exfil: Credenciais do usuário
• Indicadores: Incompatibilidade de domínio, ofuscação de JavaScript, formulário para credenciais
• Risco: Alto
The attacker is attempting to steal the user's login credentials by mimicking the Juno login page. The user is tricked into entering their User ID and password into a form.
Pages with identical visual appearance (based on perceptual hash)
Found 2 other scans for this domain