Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T174331CE93851B0164B7380D390AF2A4AB33D142FB81C55A0A174DFE975F88A5606FF9F |
|
CONTENT
ssdeep
|
768:UyWuP27p4qubW8n+y/u5D15//LCs1QzWwX8Uxz23yP2CWKnat0MIllSxHyOzxHRS:JsdyOloQzZs8oWQbp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ee3139ce9ac311c6 |
|
VISUAL
aHash
|
81818181b9b9b99d |
|
VISUAL
dHash
|
2323036365616179 |
|
VISUAL
wHash
|
818181b1b9b9bdbd |
|
VISUAL
colorHash
|
1b000e00000 |
|
VISUAL
cropResistant
|
0000000000000000,0000000000000001,8280c1999dc080a2,36a3a3a1a1a181a1,b08a63737f7c767a,c0c0c0d4c2c2c2f4,4fcd539b9f97938f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 695 techniques to evade detection by security scanners and make reverse engineering more difficult.