Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19B7233B011A41132636FCF9D70666B9DE292515FCB235404A3E99BA6BFC5EE4DCC1383 |
|
CONTENT
ssdeep
|
96:JdQrCSdlIJFU1ea4+tP9GZK3g4ulr2caVmoheSl5X+MuS3vAco3UP33MgRj+xG5Y:srNED+x96haPFI83lj+rGciBLbxkYs |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
99666c31969bc66c |
|
VISUAL
aHash
|
00003c3c00181818 |
|
VISUAL
dHash
|
a21060680452b2b0 |
|
VISUAL
wHash
|
5a3c3e3e1c18181e |
|
VISUAL
colorHash
|
38c00000000 |
|
VISUAL
cropResistant
|
0f23273633332b0d,9999999898988c4e,29adc5c5ca683444,faf4f4e4908a4206,a21060680452b2b0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 486 techniques to evade detection by security scanners and make reverse engineering more difficult.