Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C2530D319841993B01DBA6D4A676176B26E68344CB230648BBF8C3F95FDFC18CE3B165 |
|
CONTENT
ssdeep
|
1536:OksIxo4gk5jkW2k8OBk5+kWBk8OUk5mVn2PXXCOgo2gqMP37eee/eeeceeeSXXdF:OkQSnnRMP/87T |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9206f54a746f38ea |
|
VISUAL
aHash
|
007e1e3e3c18ffdf |
|
VISUAL
dHash
|
ccf8f8f8f9f9713e |
|
VISUAL
wHash
|
007e1c1e1c187fdf |
|
VISUAL
colorHash
|
062010001c0 |
|
VISUAL
cropResistant
|
f878f8f9f979b13a,3c7870e0e060e0e0,0cdcf0f8f8f9f979,9397979fb4b4bf7f,4a6a2a9f9d9c9c9d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 67 techniques to evade detection by security scanners and make reverse engineering more difficult.