Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1678142715158F93B424291C9B2A2AF0673D1C28BCB661E0097EAC79E6AD5CB1F9130D5 |
|
CONTENT
ssdeep
|
96:iJdrJd8WbJGiaUJTiskFcYkE7SpzlpZhpc:4fKWlGiauTbkOYkI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e3414862a69dbf36 |
|
VISUAL
aHash
|
000000ffe7ffffff |
|
VISUAL
dHash
|
d29053028d4e0008 |
|
VISUAL
wHash
|
0000008be7e7ffff |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
f2829292929282f3,931b27529b9d94c8,53720c4d0c000800,60e094d2d2907060 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.
| ID | Português | Inglês | Trigger |
|---|---|---|---|