Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15F833BA5350CFA271AB343A750DF24077379121B48094C70B295ED6EA1F8C9BB1ABFD9 |
|
CONTENT
ssdeep
|
768:NaruM0veC0ayKS4UfINc2iRaZls02bybMdN/zgsk0Y16JPYLOT6CHoZuGOjjgquQ:Nve+bU1RSs02ObI/i3UwLVCcuGOjjRnD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b4e1c9b4e8e8b48e |
|
VISUAL
aHash
|
ff40064406060000 |
|
VISUAL
dHash
|
d6dc8c8c6c0c0400 |
|
VISUAL
wHash
|
ffe6066666060600 |
|
VISUAL
colorHash
|
38e02000000 |
|
VISUAL
cropResistant
|
0004608696966004,0000104c4c081000,d1dc8c8c6c0c0304 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2382 techniques to evade detection by security scanners and make reverse engineering more difficult.