Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A2839631A2852403A15785C8F1328B4A73978789CF134B7477F867E6FACECF9696129C |
|
CONTENT
ssdeep
|
1536:rzcGkPGC9QXtC9QXu8UeBZp91C9QXi0C9QXg3r4C9QX2km38zeC9QX6C9QXraaC5:T/u8Viygbm2xNkzdhxjQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93cda63939c1966c |
|
VISUAL
aHash
|
7c307e4e080e6e46 |
|
VISUAL
dHash
|
6967e49a9a98c88c |
|
VISUAL
wHash
|
f1f17f4a0a0e6a46 |
|
VISUAL
colorHash
|
02200038000 |
|
VISUAL
cropResistant
|
6967e49a9a98c88c,ceb96c9866f43125,d9732369232f360d,2764e7f7e3ca6821,d7693248cccc442c,9597e328d0e0f090,9796c569a271f1e1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.