Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12141942311045D2BA18343C9F760B67EB2D74386CA056518D5FE43B9C665D45FC372E4 |
|
CONTENT
ssdeep
|
48:bX8jBNTNmTNM9w0pD6ZR5BnqWiQRnkgB51GIiEHLTxeQx:Lc7wmD6ZZnWQRn7DxeE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
db5e16191b263c99 |
|
VISUAL
aHash
|
083cffffffffe700 |
|
VISUAL
dHash
|
7048a0aa52080c0e |
|
VISUAL
wHash
|
0018ffffefdf0000 |
|
VISUAL
colorHash
|
07003000180 |
|
VISUAL
cropResistant
|
7048a0aa52080c0e |
• Threat: Phishing Gate
• Target: Grabix Pro users
• Method: Bot detection bypass
• Exfil: Unknown (hidden behind gate)
• Indicators: New domain, obfuscated JS, suspicious gate
• Risk: High
The site uses a gatekeeper to hide its contents, likely to deliver a phishing form once the user interacts with the 'Bot Protection' check.
Using JS obfuscation and gating to avoid blacklist detection.