Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F941ED339008541F131359D6F466336FA5D7860ECF672C60B2FA07A64BE5F95C87285A |
|
CONTENT
ssdeep
|
24:hR66PAuVGa8D+KoXXXNXefXNNxBaD7xw/wN/yN/t94Z1k5Rdz00AhDSo4W1voTyO:TjBkTx/m/NaN+1oR52hejqvPP+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
98ad8d8a39ec720f |
|
VISUAL
aHash
|
9f5bd8c0181c1c0f |
|
VISUAL
dHash
|
b3b6b2b2b1b5b19b |
|
VISUAL
wHash
|
df5fd8c0181c1c4f |
|
VISUAL
colorHash
|
0e603000000 |
|
VISUAL
cropResistant
|
75e7a6a6e6e6e3c7,6060e4d3f3e3f7d3,581ab6587624cdc6,3a1c0ec6d47278b0,d3f151d1d8bad0e2,c61819a5a66c959b,c9898ace66262ee8,9e3cb8e9e2869ca0,a2aecca4a4945273,27c9852717263626,b3b6b2b2b1b5b19b,e869492d2d2c2d05 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8800 techniques to evade detection by security scanners and make reverse engineering more difficult.