Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1893319E93855B5135B6281D3A0EF3A5BB33E246F780C55E06160DEA970F84A9503BF8E |
|
CONTENT
ssdeep
|
768:zyWu8n+WPy/u/sC11R5SM9XcNwGWirDLjwX8UY3uo3oiTpSxHyOzxHRBaW/Sy3sj:1oKyOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8818d650e9e756f6 |
|
VISUAL
aHash
|
1f0f0f0b0100ffff |
|
VISUAL
dHash
|
f873fdd3bbbc6b23 |
|
VISUAL
wHash
|
1e1f0f030100ffff |
|
VISUAL
colorHash
|
07c00018000 |
|
VISUAL
cropResistant
|
f8f3fdfdd5d3ebbd,fdac9876546aeec7,53e3e1b97cfeff2f,8e8e8e39598e8e8e,59211f1f23232322,fcf3fdfdd7d3bfbd |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 694 techniques to evade detection by security scanners and make reverse engineering more difficult.