Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12404D8F2F0B15D77425B53E6A26A3A9A7986D346C782079582F0D35CCFD2DE0EE2244C |
|
CONTENT
ssdeep
|
1536:RliIgxIgbUkBnXm/oFOW3L+B9JV+bWGoIgilIgqTt/:wL+B9Jj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bbc0959cc4317b3c |
|
VISUAL
aHash
|
ffff81a1818183c7 |
|
VISUAL
dHash
|
aa0f4d4d65791f17 |
|
VISUAL
wHash
|
ffff81a1818183c3 |
|
VISUAL
colorHash
|
0b0000081c0 |
|
VISUAL
cropResistant
|
085f4d4d65591f17,fef24155173e7040,e49f97bfa72e06fc,b5b1297db2a54c45,d9e5bfffcdcee6e2,b7ba995959552421,3abb5454484d3232,b2c216372526daa2,7dfcd2a9ad55adad,00000432b2b20400,9ece8ea5d515beb6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 9 techniques to evade detection by security scanners and make reverse engineering more difficult.