Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T190828432A258393E4AC316D1EB51A77EB3A78782E2011A1449FCC7B81BD6F0DFD32556 |
|
CONTENT
ssdeep
|
384:Qr6FakrNLr6AO5DFuqMvII/XQFsSIIyinA8jwT6rUHUGaOWX5OAR5OA1sRppuUFt:Qr6FakrNLr6AO5D8vIIPoszIyP8kT6r2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
876f53921a6cc46b |
|
VISUAL
aHash
|
203131313fff307c |
|
VISUAL
dHash
|
c4c7c7e7ffe0c5d4 |
|
VISUAL
wHash
|
203171313fff703c |
|
VISUAL
colorHash
|
00000030000 |
|
VISUAL
cropResistant
|
75759c8aca5acaa4,cde7c7c7e7e7cff0,d159d2d6a6a627d9,ced648d6c6466767,6969339ab48e843a,92b3b3cacaca9c94,4ecc4cca9a9adbaa,504c4492b29a9842,2a22565cad92a844,c4c7e7c7e7e7efd8,18c0e488d5d5d4d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.