Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T128E3CD7186917C37953E8DC8E2A0DB0EE0EF923FDBD64505A2E4B3A50BCBE64F541216 |
|
CONTENT
ssdeep
|
3072:ZpEAsr2lsFgRUrnegm10h+Pme/kHKxyd+3f/gv8lTwLuKt+l8tOlgtijYcRoBMX1:ZdloxjU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e94396b6e9691417 |
|
VISUAL
aHash
|
ff3900e1ebe7fbfb |
|
VISUAL
dHash
|
e529db0b0b0f2b22 |
|
VISUAL
wHash
|
7f0800c1e3c3dbdb |
|
VISUAL
colorHash
|
06000010080 |
|
VISUAL
cropResistant
|
d3e2e44d3323e1d1,030b0b0e2b2b2322,d1d1d1d4c0d4cccc,8c84b62584c54442,2433046466641922 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3961 techniques to evade detection by security scanners and make reverse engineering more difficult.