Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A4136A306851E83701DBA6C85636572A63E68348CA630A89FBF4C7E95FEFD5CCE27111 |
|
CONTENT
ssdeep
|
384:nclsJO5xVZjqTSt44N5WroUa87AzxmZB7Y7np86N5sZXB6ft:nclsIx/jV44VUf77ZB7Y7pdN5sJB6F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d223cced0dcac92d |
|
VISUAL
aHash
|
2000000000ffffff |
|
VISUAL
dHash
|
c5cdc9cc16840828 |
|
VISUAL
wHash
|
7860240000ffffff |
|
VISUAL
colorHash
|
06600008000 |
|
VISUAL
cropResistant
|
353c48dcd866a6be,33339ab59b9b9199,1a50d52a6a737393,8ca201c4d8d42182,0401a04c08202ca8,c3cdcfc9c98c5ec6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 73 techniques to evade detection by security scanners and make reverse engineering more difficult.