Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18B6386717602292A65AB83CFE2166E0CA1C5D38FC6551DD8F3F5431ACFF2E20BD652A4 |
|
CONTENT
ssdeep
|
768:qLhGL7NRTMnGz4oHASNhT2EkmtyokLqzRHmZmEYjIP:yhGlRTMnGz4ogehqZmtyo+imZm/W |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b96d99683634c4b6 |
|
VISUAL
aHash
|
c1c1e1c3c3c38f8f |
|
VISUAL
dHash
|
1313232f2f233b3b |
|
VISUAL
wHash
|
c1c1e1c3c3c38f8f |
|
VISUAL
colorHash
|
06240600000 |
|
VISUAL
cropResistant
|
848a929393989e96,4d8d5dfdcd4ddd4a,e3a1f0b0f0f0f01e,10294d4f8e645ddd,460e0e8fd8c59839 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1074 techniques to evade detection by security scanners and make reverse engineering more difficult.