Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F72329203211B36E5D334F74F3493169D1AED384E4A2B86DB3A9829132D3279CB5BDD9 |
|
CONTENT
ssdeep
|
768:2m+0wA3wnHAXbRYP8hPsL4R3E4tJ/8jAPoPKPlVgPvSBAP2qDZ7U1c/zP0GPbSPW:2m+0wA3wnH+bRR6o3E4tJXcSbqDZ7U14 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b19b9b66649a8e64 |
|
VISUAL
aHash
|
efe7efc3c3e7e7e3 |
|
VISUAL
dHash
|
5d1e1616961e1e0e |
|
VISUAL
wHash
|
87c7c3c3c3c3c383 |
|
VISUAL
colorHash
|
07000008600 |
|
VISUAL
cropResistant
|
5d1e1616961e1e0e,040e9b8e4e8aae54 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 428 techniques to evade detection by security scanners and make reverse engineering more difficult.