Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13A230D721243693F8A87A1C5FB792B4AB2C6930BC6630D01B7F6871A9FC6D24FC19561 |
|
CONTENT
ssdeep
|
768:vlBzBOBkBRBzB9Deee6eeeV8eeeWx2HLpakp72VP2YNeJHy0NNrzGNt9Zs+GPTnP:vlBzBOBkBRBzBdeee6eeeeeeeWx2HLpL |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ebb19ec2ce057548 |
|
VISUAL
aHash
|
ffff80e160200080 |
|
VISUAL
dHash
|
c5191a0bc9c1c149 |
|
VISUAL
wHash
|
ffffc3e1e06020a0 |
|
VISUAL
colorHash
|
0f6c0000000 |
|
VISUAL
cropResistant
|
54548c414d4d011a,a323a6a522ab6c20,1e339acccc9a6d99,004030c6ce314000,1a1b4bc9c9c14149 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 100 techniques to evade detection by security scanners and make reverse engineering more difficult.