Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1615409B5930C756F204B8BC8EA727634E36F95BCB57A42A08E6FC7710587CD4EA1B850 |
|
CONTENT
ssdeep
|
1536:hyRlDIX5s7xi+8dv5/+PXi5S/L5UYN9/YB2i8eeSy8Air+8EsNn74ari25vBDxuA:hynxpx7ZwaedyI6yacSx+1QEjOU+k |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f15b4727343ca4b4 |
|
VISUAL
aHash
|
0000ffffe7e7e7ff |
|
VISUAL
dHash
|
cc580b1b161f1f1e |
|
VISUAL
wHash
|
0000ffcfc3c3c3e7 |
|
VISUAL
colorHash
|
00000030040 |
|
VISUAL
cropResistant
|
58043b1e0f1f1f1c,808080808080a001,dcdcd1d1c8cb1818,010101111101013a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63933 techniques to evade detection by security scanners and make reverse engineering more difficult.