Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T152B12D716140A82B0293E3E6E339E71FFAC1A269CE170726A1F4C38D5FE2D50DD46625 |
|
CONTENT
ssdeep
|
48:nxD0x6LUdKs1osJosRlG4OwhlvS7YvS7qGa2obmTeTxTFn6TFU0pF+u71W92vFkg:N5Hwb6L7w2kmTen0pF+SGGFFNOj+2qEC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3ac13ea8cb80e9d |
|
VISUAL
aHash
|
ffe7ffffffe76624 |
|
VISUAL
dHash
|
4f4d4e144e4d8ccc |
|
VISUAL
wHash
|
a5272fc7f7a14424 |
|
VISUAL
colorHash
|
07000011080 |
|
VISUAL
cropResistant
|
4f4d4e144e4d8ccc,b8bcbe9aa69e1efa,dac3c64c4c161379 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.