Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11276AB19805644770D5618D1EAD0EBDFBC21ABB5F333C42071B10BE5E8B2D9B788B6B9 |
|
CONTENT
ssdeep
|
12288:H2/ADADADADADADADADADADADADADADADADADADADADADADADADADADADADADADk:9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
de405fa7398c64d2 |
|
VISUAL
aHash
|
183c76dbcde79c88 |
|
VISUAL
dHash
|
3369cc32194c6539 |
|
VISUAL
wHash
|
103c76dbcda79c88 |
|
VISUAL
colorHash
|
03007000000 |
|
VISUAL
cropResistant
|
3369cc32194c6539,0513264cb870e4c7,40201884c2e1301c,6170380e87c3e179,31385c2e0bc5e373,c2e1709a4d170b05,e4e8d1268c102040 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3223 techniques to evade detection by security scanners and make reverse engineering more difficult.