Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T145C2D57512482A3E960386E8F761F33C816DD2AEC62B8A58F3BC12A157C7DD5D9237C4 |
|
CONTENT
ssdeep
|
768:Uomn6sMDakobaHmaw1LMZ8hBOj9G85vkaNcFK:xmG2b+HRw1LEPvkgc0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9043f898c7b8c7ab |
|
VISUAL
aHash
|
ff000000001edfff |
|
VISUAL
dHash
|
ebcbcacae8b43236 |
|
VISUAL
wHash
|
ff012000007fdfff |
|
VISUAL
colorHash
|
02001680000 |
|
VISUAL
cropResistant
|
6b6b6bdae8cacbeb,313cf8facacec7cb,7949a9e93132a429,f4b4363b37353002,eaebcbcaeac8e8f4,ffe7f3feb8f5b2f2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.