Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T111B274B3A189C73313DB43C4A725B72E73514245CA62190967F4439FEEE5E94E83F988 |
|
CONTENT
ssdeep
|
768:2bsV6WVqEqtfW44qGK6CPCQbOPgYJIX8z0QZ:wPy4wcI00 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93b3266cd96c246d |
|
VISUAL
aHash
|
006e676c6c00003e |
|
VISUAL
dHash
|
88ccccdad8e4d4c8 |
|
VISUAL
wHash
|
006f6f6f6c04347e |
|
VISUAL
colorHash
|
38006010000 |
|
VISUAL
cropResistant
|
f9f8a4f4daf8e0e0,88ccccdad8e4d4c8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.
| ID | Portugués | Inglés | Trigger |
|---|---|---|---|