Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11EF220709115AA3B02F3A2E16BB47B5FB3C9E2C9D903470526F8D39D8FCAE94ED21151 |
|
CONTENT
ssdeep
|
768:PEvc+VgoB5KQWQvRQaQSdQ0oZ1WQ8y2ovK:svc+Vgw5NGpp0oZAQ8y2R |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92b39eef6d1cc180 |
|
VISUAL
aHash
|
24ff6e00417e1e3c |
|
VISUAL
dHash
|
4d29dc3793d428f8 |
|
VISUAL
wHash
|
24ff6e0041fe1e3c |
|
VISUAL
colorHash
|
000000003c0 |
|
VISUAL
cropResistant
|
0c000808c0e2f8fc,24d0c0b2b280d201,8e86b4accec6ae9a,a489a3a78f97afb1,c0c2838d35b39349,92b32aea62b8ace2,4d29dc3793d428f8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 54 techniques to evade detection by security scanners and make reverse engineering more difficult.