Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T140246873421974264533C2C530BA5B3AE2969E4FFA930E050FECD7FA1BE9CA0752B159 |
|
CONTENT
ssdeep
|
1536:Jvan0YLOxwOJUHWJzvhdPNLra1e80gmaqcSSSSn0bHexeLjHMg+iUwaP7j2S4wrH:dsSv8qrsFh5zp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9253ed61b96592c6 |
|
VISUAL
aHash
|
000c2e0e0e06c3ff |
|
VISUAL
dHash
|
584c4c4c2c0c063a |
|
VISUAL
wHash
|
008eae8e8e86c3ff |
|
VISUAL
colorHash
|
07602000040 |
|
VISUAL
cropResistant
|
9696b8b071318a9a,335385e723c3c3c3,06f00440303c3837,594c6c4c0c2c0c06,00102cb2b20c0000,b3abb5bab2bba3b3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 963 techniques to evade detection by security scanners and make reverse engineering more difficult.