Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T176927472A0002B3F426783CDB762F73D91E39248D7865C1996F9475E4BDAE90C82246B |
|
CONTENT
ssdeep
|
384:0zy5Ni8RTqIIIIsGj4OVs/YzMIIIII0tyRan3Td8YlgIYsOy2+y9BH4ciUIe:0zy5Ni8RmIIII5zMIIIII0oRs3Td8Y+x |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c141993cb63666fc |
|
VISUAL
aHash
|
007870200000ffff |
|
VISUAL
dHash
|
d2d2c2c864c4d000 |
|
VISUAL
wHash
|
42f878603020ffff |
|
VISUAL
colorHash
|
39c00018000 |
|
VISUAL
cropResistant
|
6352da45d5dc6c6b,6b13933353d3d5c5,3515cc8c95ece5d5,79098b8a8b8b9b9b,d080d00458988000,c6d2c2c2cc64c4d0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.