Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AE154361F381D429164381763FAFE984413AAE54EF06671BBC67CC219A8577E1B33B2C |
|
CONTENT
ssdeep
|
1536:o59bz7bzQtbzbbzObzWbzFbz8bzEbzQYbzbbz5bzpbzFbzYbzkbzQzbzbbz7bzXr:tiH7T |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d652fda85332cc62 |
|
VISUAL
aHash
|
0000000020ffffff |
|
VISUAL
dHash
|
087c4c4ccc22298a |
|
VISUAL
wHash
|
00002004eeffffff |
|
VISUAL
colorHash
|
030020001c0 |
|
VISUAL
cropResistant
|
2a2a33d353133533,a280d286869280a2,0706d02322cbaeb6,0c0838c44c2c4c4c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6748 techniques to evade detection by security scanners and make reverse engineering more difficult.