Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D792F3B1925224B325574EC6A2729B5FA0F7830CDF03045863FD8B8AA7D3CE49956F68 |
|
CONTENT
ssdeep
|
192:TJjF1M+y1f4424g58SpJHnQu8rqeOsd+aeg6GP3UxG:tjzM+y1f44Y5JpJHnQu8rXVdNeg6AWG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e31ae59cec2c92c3 |
|
VISUAL
aHash
|
00000400fffff3e3 |
|
VISUAL
dHash
|
b2c9c929ccccc6c6 |
|
VISUAL
wHash
|
38000400fffff7e3 |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
04b2b2d9d9f23284,70c0968e969cc071,2caee66eee44293a,b7b76532a2657222,94962ea7a7098585,e0ccccc8cec6c6c6,71d89abbbb92cc71,c638c9c9c9c92d43,b271555469b26960,05f3e9c9f9f3d9ff |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.