Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19C738832D357041390ABD2D9B1614B4923928789C7134FB567FD63BAFACDCB6262329C |
|
CONTENT
ssdeep
|
1536:SVO08djG7eeeeBeeIaqHefe0efepefeGeAH7Zee+efefeTete/1e07QQFzqLC+Nh:hbF4MFNQLAP/57PQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c14e3631cfcb9631 |
|
VISUAL
aHash
|
00007c7a68686868 |
|
VISUAL
dHash
|
aba7e4d2d2dadbd1 |
|
VISUAL
wHash
|
60107efa68ebe86c |
|
VISUAL
colorHash
|
02000030000 |
|
VISUAL
cropResistant
|
aba7e4d2d2dadbd1,60e8cc30cef46969,206666e6261c2c2c,cc1a1b1c41cae6cf,9905614521a589d8,d7693248cccc446c,8905654521a58998,4e5676765e2626d9,a9b2e4e5a4bdb5ac,97c46931f1e1a0ac,e5e0112141c9e3e4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.