Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AEA38573C2A06E3B27A4E7D4C7D83A3DE143005DCDD0856ACB93EB4B61E6E7A5812749 |
|
CONTENT
ssdeep
|
1536:RMrSQ8QHum57YMOVZf5xa7V92e4s+KEXtQKsW1AdTa2Uv+fccHF:RMr9IUv8KayF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e522a4f2e1a1b6f4 |
|
VISUAL
aHash
|
e7000020e080f0f2 |
|
VISUAL
dHash
|
566644c30818c4c6 |
|
VISUAL
wHash
|
e7022269ecc8f6f2 |
|
VISUAL
colorHash
|
1a000008040 |
|
VISUAL
cropResistant
|
0000000000010007,a0a0a0a0a0a08095,9296d9d9d0920240,3232a6d6a6acd696,b1b85285cd4dc187,566644c30818c4c6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 931 techniques to evade detection by security scanners and make reverse engineering more difficult.