Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12141942311045D2BA18343C9F760B67EB2D74386CA056518D5FE43B9C665D45FC372E4 |
|
CONTENT
ssdeep
|
48:bX8jBNTNmTNM9w0pD6ZR5BnqWiQRnkgB51GIiEHLTxeQx:Lc7wmD6ZZnWQRn7DxeE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
db5e16191b263c99 |
|
VISUAL
aHash
|
083cffffffffe700 |
|
VISUAL
dHash
|
7048a0aa52080c0e |
|
VISUAL
wHash
|
0018ffffefdf0000 |
|
VISUAL
colorHash
|
07003000180 |
|
VISUAL
cropResistant
|
7048a0aa52080c0e |
• Amenaza: Puerta de phishing
• Objetivo: Usuarios de Grabix Pro
• Método: Evasión de detección de bots
• Exfil: Desconocido (oculto tras puerta)
• Indicadores: Dominio nuevo, JS ofuscado, puerta sospechosa
• Riesgo: Alto
The site uses a gatekeeper to hide its contents, likely to deliver a phishing form once the user interacts with the 'Bot Protection' check.
Using JS obfuscation and gating to avoid blacklist detection.