Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11304537421401F7EC2E762F45574DB26F1B9A388EF5F8E5AF6F883872B49C06CA42911 |
|
CONTENT
ssdeep
|
768:4B6FfwqRXkR4LuNrGDaz06ZpsCxm3V5IxkJad3kRxZZrXfRJo54OHz2cd/mwVvh4:pfVRXk4m2PzFVz1v3PeEWbSF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
aad69ce8c9a1e1d4 |
|
VISUAL
aHash
|
ff1d0d0101010101 |
|
VISUAL
dHash
|
3be9c9cbeb9b97db |
|
VISUAL
wHash
|
ff7f2f6b09410301 |
|
VISUAL
colorHash
|
16e00008000 |
|
VISUAL
cropResistant
|
3be9e9cb2bd9b3dd,e9e9cbcbc99b9759 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 48 techniques to evade detection by security scanners and make reverse engineering more difficult.