Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16AF2B69B214815E5C1B38FDC982166907246EA5FC9718370C2FC4E3A2BD29A5B74CF7E |
|
CONTENT
ssdeep
|
384:pPlMorXr4rx6RzBOkvOfYgIvybe9m/Nz8bO0vsFijYK/M94UZh3gl4oyO0H74lQO:NrXr4r6B1abYhs4jY7yUjJoH0H0lQcy0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a5d22d52d22d5aa7 |
|
VISUAL
aHash
|
ffffffffff000100 |
|
VISUAL
dHash
|
0e080e8e08d60307 |
|
VISUAL
wHash
|
c3ffffe7e7000000 |
|
VISUAL
colorHash
|
17000008180 |
|
VISUAL
cropResistant
|
0e080c0c160e0c14,b6b7aba3cbaa5551,c6c7171707170606 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 43 techniques to evade detection by security scanners and make reverse engineering more difficult.