Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18B632061A045EE2740DB66D59133536523F2834AC7231AC8B6F9C7FA4BDFC68EA33254 |
|
CONTENT
ssdeep
|
768:TC1U2fsIx/jsdZKm20+A8Zy3MTjM1lMMwUf7ZF:TyUosIxoWm2zA8Zy3MTjM1lMMf7ZF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ebb2944db396640b |
|
VISUAL
aHash
|
fffffdece0d01000 |
|
VISUAL
dHash
|
2a29455d9393e14b |
|
VISUAL
wHash
|
fffdfde9e0c00000 |
|
VISUAL
colorHash
|
074010000c0 |
|
VISUAL
cropResistant
|
2a69415d9113a141,0000020000000000,1d5b333321652434,455d599313a14143,991d2e0f3f797579,4f0f4c4e1e2f3f06 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 163 techniques to evade detection by security scanners and make reverse engineering more difficult.