Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T134240F55E1AA353B835B83E9F62673A911EB91CFD4D80485F9B706F433B1AA8F00D5C2 |
|
CONTENT
ssdeep
|
1536:mHOw9ymrrKn9ymrrK+5lzzZt/4HEEiyr3ftpj3Byhdc90gF83aewLKF+YFFlAd5U:gxymrrK9ymrrKe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a3f2ac4cec4e8c4d |
|
VISUAL
aHash
|
ffefefe720000011 |
|
VISUAL
dHash
|
ec8cc8ccc6e4e3e3 |
|
VISUAL
wHash
|
ffefffe720000011 |
|
VISUAL
colorHash
|
0ec00008000 |
|
VISUAL
cropResistant
|
f0f1c1e1f9f1f192,68cc80808080e060,032020000080a2a2,ffefbf1f9b9a0d8f,f8e4c3830c8d8b82,ec8cc8ccc6e4e3e3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2805 techniques to evade detection by security scanners and make reverse engineering more difficult.