Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CBA3CD234219352A4437C3C1346A5B3BD1A6999FFEE60A404EECCBFA2BFDC90745A15D |
|
CONTENT
ssdeep
|
768:Gi00tpR4nXF6YjOpSpFlTC6rrWQyYOh8ymEICSzL8:GiVtpR4nXBKpSpFl26vRy8wI38 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d23eed2dd390bb00 |
|
VISUAL
aHash
|
c0800c2e0e0178fc |
|
VISUAL
dHash
|
2222d8dcd80b8288 |
|
VISUAL
wHash
|
c2d00c3e0e85f8ff |
|
VISUAL
colorHash
|
11400030000 |
|
VISUAL
cropResistant
|
900080606088003e,2e80a0e0e0e080ac,8200a06060800002,06008080a0800026,e492b2c2ab181980,fa7c7cfa80f1b8be,6466f0f0f0e0e2e0,222298dcd84b828a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 113 techniques to evade detection by security scanners and make reverse engineering more difficult.