Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AFE219B2308014AB1A53CB88B5C1B52CD0D2F64FEE17C5D4D2DF51AA9AC6EF3C872685 |
|
CONTENT
ssdeep
|
768:+hBlbjOpml2iqdtKxrd5yY2KYdY3Y6Y5N2walKK/cXhMQrA30YlIRR8ms:UVPU1doQN2fHj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
992fea222c8b8eab |
|
VISUAL
aHash
|
01033f3e060e1c1c |
|
VISUAL
dHash
|
5bb3f2febcecf8b0 |
|
VISUAL
wHash
|
030b3f3f070e3e1e |
|
VISUAL
colorHash
|
38200040006 |
|
VISUAL
cropResistant
|
5bb3f2febcecf8b0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6255 techniques to evade detection by security scanners and make reverse engineering more difficult.