Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B261633590298E135483C6D8B7F49B0B378A8396C74B6B045EF4627C6FD7D46CE222E4 |
|
CONTENT
ssdeep
|
48:eKw9p+u0Onw+9o3DZxkbfW0OnYuIzBtx2dplmjneICbHtibs73Z:JgZwJv0fCYB7wlmdUOy3Z |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
99cc663399cc6666 |
|
VISUAL
aHash
|
00181818182c1800 |
|
VISUAL
dHash
|
083032322a2a300c |
|
VISUAL
wHash
|
1c1c3c3c1c1c1c1c |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
083032322a2a300c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 458 techniques to evade detection by security scanners and make reverse engineering more difficult.
| ID | Português | Inglês | Trigger |
|---|---|---|---|
Pages with identical visual appearance (based on perceptual hash)