Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DF219E7284C15C3F93F2C269DBB1B3281B558988C3C25E8856E656CD07CDE5288A62A8 |
|
CONTENT
ssdeep
|
24:n9CYCECqRmtvHg5mcIoAy4b7RT7LN1aGlGpiF9:njmNHg5m5vLaRu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a55a87db16c324d3 |
|
VISUAL
aHash
|
3e0083a3c3c3ef67 |
|
VISUAL
dHash
|
6c2b464e1e06cae6 |
|
VISUAL
wHash
|
3e0083a3c3c3ef67 |
|
VISUAL
colorHash
|
01000e08000 |
|
VISUAL
cropResistant
|
9e16161656561612,82e1888380f00303,2088c0d1d2d880d0,1020000232c20638,7c53db8c98d8eca4,6763c5d4b2cd26f3,0fd7d040402f3236,8e2fd97d6ca28ccc,635054d9999193e2,6c2b464e1e06cae6,14891b12c4052525 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 9889 techniques to evade detection by security scanners and make reverse engineering more difficult.