Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T185B196738409095B010943C3A1E3BB5AA546C119DE918F45EB540BEBEBDCFB6F237389 |
|
CONTENT
ssdeep
|
96:2c2NalVsFc3C/85gPIGI0TSZSZSZSZSxoNsAPMF+k1gUt/Py3SvDyDLK0486:2c2N8VsFcS/85gAf0eIIIIxoNsAPMF+E |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8cc973267333cccc |
|
VISUAL
aHash
|
0018181e1f1f0702 |
|
VISUAL
dHash
|
92b2b2b2b2b2b634 |
|
VISUAL
wHash
|
08585e1f1f1f1f07 |
|
VISUAL
colorHash
|
3000b001200 |
|
VISUAL
cropResistant
|
92b2b2b2b2b2b634 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.