Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EA51936210119C3B924392E8A6E4A607B4C0D247CB671900A2FD67AD1FEBEA6ED33194 |
|
CONTENT
ssdeep
|
48:T7nTzPhi7tIZoEmM7zuGNQty86S/pHz4jhBaPUNx+TQhkA:TbgG+EmMnKty86EWjq7TukA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
83da9925f9d96606 |
|
VISUAL
aHash
|
3f3f373f3f373f3f |
|
VISUAL
dHash
|
d0d0c5c6c6c6d0d4 |
|
VISUAL
wHash
|
3c3c342020203c3c |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
80808c8c8c8d808c,e384acb6b6ac84e3,00081671310e1000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
| ID | Portuguese | English | Trigger |
|---|---|---|---|