Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15471FC3080688C7791C3EAD8B7F59B2B3695C352CB17060547FCDB6DAAE7E85CD50285 |
|
CONTENT
ssdeep
|
96:TPt2ghi+ekfV0f1Epnau6M57/PctLiB73D:7gm2f4F7HCLiZ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
999ca663a663a3c9 |
|
VISUAL
aHash
|
3f181818181818fe |
|
VISUAL
dHash
|
f0b2b2b2b2b2b2f0 |
|
VISUAL
wHash
|
ff1c1c18183838ff |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
4809c8c89140fcfc,9eaab28e8eb23396,c0c0200080800000,b2b2b2b2b2b2b2f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1 techniques to evade detection by security scanners and make reverse engineering more difficult.
| ID | Português | Inglês | Trigger |
|---|---|---|---|