Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B8037511B1941D3B908762E6A2F5B719F3D2C294C7180605B5F983BD9FE3C71EBDA20A |
|
CONTENT
ssdeep
|
384:hzBLx8O8fTlIGXP022zWCld+2Uh5oEYN2P/HG0Rt2k3eAw1AKldewiaMOgoViq:h9LuO8fTlIGXPazH4h5oU/HVRQHPOOgA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f6725c587a72e218 |
|
VISUAL
aHash
|
00ffffffffff00ff |
|
VISUAL
dHash
|
134c0c0c30008484 |
|
VISUAL
wHash
|
00e7e7e7e7ff0000 |
|
VISUAL
colorHash
|
0e0000001c0 |
|
VISUAL
cropResistant
|
0c0c0c4d080c0000,0000000000000000,010181c023230180,000810b2b2320c10,000004c4c4040000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 24 techniques to evade detection by security scanners and make reverse engineering more difficult.
| ID | Portuguese | English | Trigger |
|---|---|---|---|