Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E973A4712292493F9547C2D5EB34AF4BA2D9D38BCA630D4AB7E68767CF86CA0FC14150 |
|
CONTENT
ssdeep
|
768:uScNtWaikpKms4D+HNBeeV5WzDoJ1n6PtRSXtV5FUuuNrzGNt9Zs+GPTnZwbbQNd:jnv9VndsjF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cf713b04bc358761 |
|
VISUAL
aHash
|
02e070f0f0f02099 |
|
VISUAL
dHash
|
a6c1c725a7e3c733 |
|
VISUAL
wHash
|
02f0f0f0f8f8719b |
|
VISUAL
colorHash
|
38006001080 |
|
VISUAL
cropResistant
|
a6a5a5a4a5b5929c,a6c1c725a7e3c733 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 139 techniques to evade detection by security scanners and make reverse engineering more difficult.