Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17C83E670B042763702274BD5606BA71A72BBE20FD94F0400A6B8EBCA5FD7C65D4A7789 |
|
CONTENT
ssdeep
|
768:P2JNta2cIYpRiM0owiNOOq0oMtcCE7cbvrNP+Q4c7jMMI9Uf4zX//hy7BWk20++J:npRiM9nNOOq0oMtcCE7ghqc712//nQ3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c39c636b6c98c3b8 |
|
VISUAL
aHash
|
00067e7e00606060 |
|
VISUAL
dHash
|
874cdcf44acacccc |
|
VISUAL
wHash
|
c10efefea0e0e4e0 |
|
VISUAL
colorHash
|
30003000080 |
|
VISUAL
cropResistant
|
93b88cc9d858d4d4,f3e659d0f071789c,389c903072733931,b59652134d869e34,18307c61ece0f0f3,25a19b939e5db1a4,874cdcf44acacccc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8789 techniques to evade detection by security scanners and make reverse engineering more difficult.