Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T194933DF1A1B051BA014BE3D4FA367B19725762F9DB9247C582E4CF986F8BC48DC1AC84 |
|
CONTENT
ssdeep
|
768:Qgvc34SiXM/JpfLVjEGfr4bkOy8WcYxH2Qzx/KFL7K3xdXmbygdlo0Iz5zie7tBp:bvc34SXFEGfrH8Wj0Q0dK3GtlAxPE+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b83ac7473b4b4938 |
|
VISUAL
aHash
|
00ff838787ffffff |
|
VISUAL
dHash
|
792e3b1b3e2a23f3 |
|
VISUAL
wHash
|
0083838187cbfbff |
|
VISUAL
colorHash
|
07000200038 |
|
VISUAL
cropResistant
|
793e3b1b3e2a23f3,041a5a7a3a1a5a04,c9d1c1c061b1b37b,000000402020a0e0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 15 techniques to evade detection by security scanners and make reverse engineering more difficult.