Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T136B342214557243722339F806BC5AB7D518B62D8A737CE07F6F44F2AAFC4E94A94C21E |
|
CONTENT
ssdeep
|
768:ZwOiomfH4smfOUkmpYZ6AHpk70gGoyP4bOcOuNI7LatA0hl:OOio+4s1U3pYbGggGoyPaOl57Ohl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
be1668006be939b7 |
|
VISUAL
aHash
|
00848f812404ff81 |
|
VISUAL
dHash
|
672c2a2b6ccc0f2b |
|
VISUAL
wHash
|
00869fbf2706ff81 |
|
VISUAL
colorHash
|
02000000007 |
|
VISUAL
cropResistant
|
76ebc29b98d8c2c2,aa8e8ea2b2ae8c9a,8681f07c1e4c4c59,80828a7323b280a0,1484334d4dd42b2b,476c2c2a2b6dec9c,2b2b2b3b4c544e4b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1331 techniques to evade detection by security scanners and make reverse engineering more difficult.