Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CB93EAB180449C3794D3E6D096719F6F72CAD38ACE1B0706A3FA839E4FC6DA5CD161A1 |
|
CONTENT
ssdeep
|
768:8IKNJCu+3EQgxX8/WTCx+16yUC4egwcXjCCUAC0ZJVqIVAS92ELyooBCj0ehjQxZ:MJCQ9/+xgvUnvACxCGXCQU8uNaY/9Pl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce80317b8be0e6ce |
|
VISUAL
aHash
|
7e7effff3c000000 |
|
VISUAL
dHash
|
48b4e4f569485171 |
|
VISUAL
wHash
|
ff7e7f7f3c000000 |
|
VISUAL
colorHash
|
30600030000 |
|
VISUAL
cropResistant
|
041a5b1a181a5a04,fd39bc6cec6c1c5e,4f4bbb84e4a6585c,7e3e5e7e3efae0c1,e8e8d4d651d3ebeb,3871eaf4ebe3838c,6549416551534b53,4100828280410141,c8b4e4f569465171 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 214 techniques to evade detection by security scanners and make reverse engineering more difficult.