Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T105D24130A140A93B028393C0AB74AB5FB7D29348DB53570A23F8D75E5FCBD85CD26666 |
|
CONTENT
ssdeep
|
384:8HgctZZGLR8CJtB1pXGSCMc6Tdhj5T0f0Pz0SSHYG0tft:fctZYVvjaM1Tdhj5T0fRSSHFqF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b6bc899a5e616156 |
|
VISUAL
aHash
|
ffff420000000000 |
|
VISUAL
dHash
|
32358e8e2cce4d61 |
|
VISUAL
wHash
|
ffffc6428400e531 |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
03233034343020cc,0947a289892412d0,0946201109449480,0c8e8e0181a5a5cd,c000089048c8d0a1,51792cf362002007,8c8e0c2c8ecb6d63 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 322 techniques to evade detection by security scanners and make reverse engineering more difficult.