Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T172C3A4ABC3516B7FA74497C0C7903A2EBB0300ADDD51C959C286CF4DA1B6EA2E85364D |
|
CONTENT
ssdeep
|
1536:RH7CMLTz9ATMsV9tHUpTAxNNIfDDdLE3wpPifsm6QjSudKDr7bsvFLrh9aq/Hx:RHWTnR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b4e1a6b0e0e6b1e6 |
|
VISUAL
aHash
|
e70100e0c3cf3617 |
|
VISUAL
dHash
|
0673d4848abaec6c |
|
VISUAL
wHash
|
f70100fcc3cf3617 |
|
VISUAL
colorHash
|
19000008080 |
|
VISUAL
cropResistant
|
0000000000000000,a0a0a0a0a0a08081,0c8ecf27a0aaca89,2c33f3e849c8cac9,2a4a6c6c6d499a9a,c84869a9e96a4808,b4b7373672747475,dbdb26a5a52413db,0673d4848abaec6c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 936 techniques to evade detection by security scanners and make reverse engineering more difficult.