Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T185634364A842FD3F91CB89D55172536AB2E58700CB138686BAE5C3F84BDAD9DCF32114 |
|
CONTENT
ssdeep
|
768:Z4yEcKG2eOI06MPzLv/K92OPSqtCYs9zKNS/HTBogZf9u9oLQufMEqSw+x94nAse:nOI06M7Lq9NFtCYs9mYbZfxKAs2R57x |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f474f13321b4b456 |
|
VISUAL
aHash
|
c0e0d00000ffffff |
|
VISUAL
dHash
|
8e842486523c142a |
|
VISUAL
wHash
|
c0e0c08000ffffff |
|
VISUAL
colorHash
|
07203000001 |
|
VISUAL
cropResistant
|
84c04a8894ccc891,f272636292d6d272,94988c9c9098d8d8,c0303c3c02162a2a,8e8c8404a48602ec,3a3a4c191bb0101b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 23 techniques to evade detection by security scanners and make reverse engineering more difficult.