Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15BA26573A1554C230157D2E9E270972F32C1D389CB630B86A3F9539E6FCACAAED11198 |
|
CONTENT
ssdeep
|
384:n6erP7eeryO5Yc3YVGgRrugRNmiSm9InrKInRM99X3mBdmGMwAiLeH/RRRYXYSaz:nvP7eeryO593cGpY+0IGIRMzHmvmG9AF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c938326d94ca96cf |
|
VISUAL
aHash
|
8181f9fbfbfbf9ff |
|
VISUAL
dHash
|
931bf3f2f2e2f3e0 |
|
VISUAL
wHash
|
018138787a7879ff |
|
VISUAL
colorHash
|
06000038000 |
|
VISUAL
cropResistant
|
931bf3f2f2e2f3e0,6ce6daaeb1c9dbe5,a367653a92d1691d,91998d5e5b49096f,cecbd858696b3121 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 22 techniques to evade detection by security scanners and make reverse engineering more difficult.