Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FCB30E234269762A4437C3D1306A5B3BD1A6998FFAE709401EECC7F72BF9C90741A52D |
|
CONTENT
ssdeep
|
1536:4itpR4nXBKpSpFl26vISZnw9kKwdNnrO8IiQS:zUMneTdNrOAQS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92656d13134b6d6d |
|
VISUAL
aHash
|
001f033f6f0f0183 |
|
VISUAL
dHash
|
ddbf76dcdcdcbb37 |
|
VISUAL
wHash
|
000f033f7f0f079f |
|
VISUAL
colorHash
|
00003400400 |
|
VISUAL
cropResistant
|
fd277cdcdcb9ab37,dcbd37fcdcdcb977,536b996363cc5515,0e430513161c3424,94330d3333051121 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 113 techniques to evade detection by security scanners and make reverse engineering more difficult.