Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T136D373313942643621AF42CFC233170E22D1E3CACA965AE5A5F4D3689FF5D98FF92254 |
|
CONTENT
ssdeep
|
3072:ihrHQGNP2M1l90g2ZM9sneCoFmXf/CJ7RopnB2J47a:ihrHQGNP2M1l90g2ZM9sneCoFmXf/CJJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bb46b1e34438b74c |
|
VISUAL
aHash
|
0000000000ffdfcf |
|
VISUAL
dHash
|
50713131335e3b3a |
|
VISUAL
wHash
|
0038980089ffffef |
|
VISUAL
colorHash
|
020000001c0 |
|
VISUAL
cropResistant
|
cf6d99dbca9a9185,c3185e1b3b3f3a3a,d058717131697113,1b1969e9eecacad9,2423bc96d7d1b9b9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 78 techniques to evade detection by security scanners and make reverse engineering more difficult.