Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T167234A726332B87842DBA1DEF7382A05B2D2998EF9C74594F5C995CD23C3C8025937B4 |
|
CONTENT
ssdeep
|
768:aQ+EsZx8/G8xGx49Daw6MLBrwcMLBtwZUcix+y9dQpUDF1E56ITmHDLBABW8KPqf:aQ+EsZ/8xGi9Daw6MLBrwcMLBtwZUXx8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d1eaca6a95919de0 |
|
VISUAL
aHash
|
ff40fa0e4200606e |
|
VISUAL
dHash
|
1a85cada8611cada |
|
VISUAL
wHash
|
ff60fa6e4200e0fa |
|
VISUAL
colorHash
|
31008010400 |
|
VISUAL
cropResistant
|
00000c0c0c080000,6668f0f0e0e081f1,714d233b6b196175,e4ccd4e0e0e0e0e0,60514d4f33396b27,1281cada8619cada |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 18 techniques to evade detection by security scanners and make reverse engineering more difficult.