Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D273C7750252292F92AB07D0F2A1F37C50BFB75DE68B855AA2FC41623BCDCE465123E4 |
|
CONTENT
ssdeep
|
1536:mgd9szVVAaa+LACK9szVVAaa+LACK9szVVAaa+LACKniocbwvYglCkaaCItf/VIg:TtftIkT7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c16c3bc6cd963e90 |
|
VISUAL
aHash
|
0040007e7e7c6e2e |
|
VISUAL
dHash
|
4184b0d4d4c4ccd8 |
|
VISUAL
wHash
|
3040107a7e7e7e6e |
|
VISUAL
colorHash
|
39c00000000 |
|
VISUAL
cropResistant
|
d9913131a1b2e64e,d3c1d4eccc983694,606868486889b131,70f8f273f2dc9d67,f77c6cccc48090b8,b1b1309caeb5961b,4184b0d4d4c4ccd8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5 techniques to evade detection by security scanners and make reverse engineering more difficult.