Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T156A2C82250D9657F453A49CDD272772CA0D25189CE1A1800E56E4FAFD2FEE98FC2B2CD |
|
CONTENT
ssdeep
|
192:awMqXYJ/T+klXxc2q9KvheqwoTvnuCHUXGxcy3gHJBJqK0oodIXj:2P+klXrqkpeqhvuCWGNgHJjqFo7j |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b2adac969740dd68 |
|
VISUAL
aHash
|
ff01c06c2e0e00ff |
|
VISUAL
dHash
|
bf9f9cdc4c4c9dad |
|
VISUAL
wHash
|
ff01c0ecae0e00ff |
|
VISUAL
colorHash
|
0a609000200 |
|
VISUAL
cropResistant
|
0026bcbfffbd8d97,e630c8e4f2b2b999,3a2c263626b3cbe6,e6f1381cded61e9e,a280a2c2c2a280a2,8080a2e2e2a28080,a280a2d2d2a280a2,da98d85ede989a30,a280a2d2d2a280a2,a900000000000000,bf96dccc4c4c9d8d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 64 techniques to evade detection by security scanners and make reverse engineering more difficult.