Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EE92C331A150263F1263C3D9B761B72EA0D382CDDB46181542FC4B9E9BDBF90CE2756A |
|
CONTENT
ssdeep
|
384:KtGpy5NqogUur2lhoesMNv0fmg6xKQnKjxq4ObDbmnz3nIYsOy2+y9BH4cUUIe:lpy5NqAnv0d6xKQnWxq4ObDbmz37sOy8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c343fd3a9829929e |
|
VISUAL
aHash
|
002020000000ffff |
|
VISUAL
dHash
|
9cc8c0c3cccc9300 |
|
VISUAL
wHash
|
00f07070240fffff |
|
VISUAL
colorHash
|
39001000180 |
|
VISUAL
cropResistant
|
100c32b2b2300800,0080800270908000,9cc8c0c8c3ccccc3 |
• Ameaça: Coleta de dados
• Alvo: Usuários financeiros
• Método: Plataforma de trading falsa
• Exfil: Envio via JavaScript
• Indicadores: Código JS ofuscado
• Risco: Alto
Uses a professional-looking interface to lure users into registering, harvesting PII for lead generation or direct financial theft.
Hides submission endpoints and exfiltration logic within obfuscated scripts to evade automated analysis.