Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1649274F0D226993340E3C2E1B67A2B1F72F18389DA9B125652FD83AD8BE6C50ED13155 |
|
CONTENT
ssdeep
|
384:rFRY45f1F0pI2VDeNiL9nQBCKLqsbwnu9CO+Vr7MZxbml86dNsRJ:xRY45f1F0pI2VDeNiL9ntKLqkZCOOrwj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c363973c3c3c3cc1 |
|
VISUAL
aHash
|
0264666660007e7e |
|
VISUAL
dHash
|
36cccc8cd2cccccc |
|
VISUAL
wHash
|
0266767678047e7e |
|
VISUAL
colorHash
|
38000000006 |
|
VISUAL
cropResistant
|
95998597db8d6971,36cccc8cd2cccccc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 35 techniques to evade detection by security scanners and make reverse engineering more difficult.