Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D161D9A20044A8070522B9D1EF56BF05A4724706DF4F46B2ADDC46A9EEEDDF0CC6B7C6 |
|
CONTENT
ssdeep
|
96:mubn2NG2m8pRmkY33GxEMK/xDTQmGkzSQl2Luk:l2NNLmkGGxEMK5DTFGk+BCk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8ac8cb351d3d3267 |
|
VISUAL
aHash
|
187d7d3c1c00187d |
|
VISUAL
dHash
|
f1f1f1f1f1f9f1f1 |
|
VISUAL
wHash
|
3c7d7d3c1c04187d |
|
VISUAL
colorHash
|
00003000180 |
|
VISUAL
cropResistant
|
f8f8f0f8f8f9fbff,ffffffffffffffff,f8f8f8f8f8f8f8f0,ffffffffffffffff,f1f1f1f1f1f9f1f1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 16 techniques to evade detection by security scanners and make reverse engineering more difficult.