Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18B316462002859AE6F03A8D473C6761F948BC60BCE32429DB2FA12FD19E5D9FC474699 |
|
CONTENT
ssdeep
|
24:kohgTtcuRhgTtcwhgTpkG3uY6duDWyP++BRNc1HZPdePej5k6DNEruu/1EcMGeS:4RcucRcFtP316dCWyxiHOPejZarBX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b43cdb0725d9c307 |
|
VISUAL
aHash
|
0383c30303ffffff |
|
VISUAL
dHash
|
3eb6b6b6b6560004 |
|
VISUAL
wHash
|
0000000000f03030 |
|
VISUAL
colorHash
|
07c00000000 |
|
VISUAL
cropResistant
|
78e0d0a4a0a4c0e1,3eb6b6b6b6560004,80262ea8a03333a8,e88e2341804286e8,e8d6a2a02182ccf0,e1b8e4cae0d2e070,78e0d2f0d2e4f8e1,e09c9280a192d6e0,6f8b989d8a8c946b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
| ID | Português | Inglês | Trigger |
|---|---|---|---|
Pages with identical visual appearance (based on perceptual hash)