Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E15241A2D244EC3503AA81D4F671AB9F7B50C281C74A0F9453F4533FAACDDB28A32599 |
|
CONTENT
ssdeep
|
192:BvgeAzYhhS0Xp/P8iERWYkj9YLDCywQcSLS9SBe0YDWHj0t8Cz3oehF30dPSPuPb:BvgVGS0Xp31ERWRufCFTLt8F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b046addeb0e887f0 |
|
VISUAL
aHash
|
ff000000007fffff |
|
VISUAL
dHash
|
2c048e8c8c4c1e9e |
|
VISUAL
wHash
|
ff00000000ffffff |
|
VISUAL
colorHash
|
32001200040 |
|
VISUAL
cropResistant
|
00004c0e230d0811,e080402f175080e0,2c001e9e9e1e9e9e,34048e8e8c8c8ccc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 30 techniques to evade detection by security scanners and make reverse engineering more difficult.