Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10E73844672446AA5C2B386DC9410659061C7EF5FCE6087708A7C4E3F2BE2674A3D9F3E |
|
CONTENT
ssdeep
|
1536:EwIGAm6FAkBWWpULleLtkUv3GTix5CeaFUCHn8q1AZDEVobN+YrwnQqb6F1l6G96:EHa6F5rEV16F1l6G9ta1zPJ99R14TQff |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f2a57087a8daa19e |
|
VISUAL
aHash
|
e743ffdfff78fce4 |
|
VISUAL
dHash
|
ce8f4db963c0e894 |
|
VISUAL
wHash
|
e7030744bd70fce4 |
|
VISUAL
colorHash
|
070000000f0 |
|
VISUAL
cropResistant
|
ce8f4db963c0e894,47648c84e6f65311,8c29354d4d558889,450930b2b2320c51 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.