Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F943A67383406E77229392D191626F1AB2C985CACE430F59DAEC824CE6D5C70CE76BDD |
|
CONTENT
ssdeep
|
768:pBus+77q44P6NkvPpxhWUBXpx14FvpxepUdx/ha4PFx4AJmSekXwQl:znj44SnthHfQSekXwQl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b94e9346934719c7 |
|
VISUAL
aHash
|
dfc3c3c3c3c3c3cf |
|
VISUAL
dHash
|
2b33332b3333131b |
|
VISUAL
wHash
|
93c3c3c3c3c3c3c3 |
|
VISUAL
colorHash
|
07402011000 |
|
VISUAL
cropResistant
|
2b33332b3333131b,e2f8cca22b331bba,2babb3b2d06468f0,04323ab2b23a3204,7170f0ccccf1f1b0,69296d3331198d2a,5171e896b3b3f3d5,45723470687668dc,1d3424e4f4b47072 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 683 techniques to evade detection by security scanners and make reverse engineering more difficult.