Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12F0375F8C1CA963742D142D05A717B6976D35A8DCB033E1896ECD26ABB4DD8AEC500BC |
|
CONTENT
ssdeep
|
768:LGgFhuKHarRbJfuoLClt5oEgrzDr5ix/0dnSRWwFRL4MXtrimizu0+zVhLIEYNdN:LGTrRbJfuoLClt5oEgrzDr5ix8dnSRWJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ceb4c9991646c7b2 |
|
VISUAL
aHash
|
fbfb7610043c3c38 |
|
VISUAL
dHash
|
329245656d606161 |
|
VISUAL
wHash
|
fffb343404383c38 |
|
VISUAL
colorHash
|
06e00000000 |
|
VISUAL
cropResistant
|
0000223232320069,9245456569606161,6969717171710669,18e4e42426c8c8d8,1797a76683d7f7bf,b4bcb4bc4c4fb0b0,92444c6c40525252 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 40 techniques to evade detection by security scanners and make reverse engineering more difficult.