Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12CF298207945DC2A41DF9AC86132532922FA8386C61316C8FEB5C7F54BEFD6CDA33614 |
|
CONTENT
ssdeep
|
384:YU2URysJO5xVZjqTSH1BtfrkCsrlQOwqu7Haadl2D8F6TkHbjkiN+vx4roUa87ZF:YU2fsIx/j/ntDvsrEl2DVTcbQNUf7ZF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d49b6aaab4a4a5a9 |
|
VISUAL
aHash
|
fdf8fcfcfcf3f0f0 |
|
VISUAL
dHash
|
292900141c272184 |
|
VISUAL
wHash
|
fcf8f8c0c0f0f0f0 |
|
VISUAL
colorHash
|
06006000080 |
|
VISUAL
cropResistant
|
292900141c272184,40c0c0a08080e8cf,cfbefe9e9e9e9e9e,4701298930760713 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 167 techniques to evade detection by security scanners and make reverse engineering more difficult.