Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E293E8B127904FA92687CBA891E2B21E7156F220D7179E6013B145F49DE6BF38FC12C7 |
|
CONTENT
ssdeep
|
1536:82yX6p6Ki9FjDy6rgBQ+ym1hJ9FjDy6rgBQ+ym1hK:8tX6p6KizjDy6rgBQ+ym1hJzjDy6rgB8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ca3535594b61e9c9 |
|
VISUAL
aHash
|
0006fffdfdfdffff |
|
VISUAL
dHash
|
8e6c016931310401 |
|
VISUAL
wHash
|
0006e1f8f8fcf0f0 |
|
VISUAL
colorHash
|
00006000000 |
|
VISUAL
cropResistant
|
01020ab2b2ba4a15,b28688929688a698,2609693131300400,00dc132c6cec2c2c,031b5b0707138f1f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1846 techniques to evade detection by security scanners and make reverse engineering more difficult.
| ID | Portuguese | English | Trigger |
|---|---|---|---|