Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15AD2433186511C3F615BE3D5F524B71AE385C241CB060AE5A3E8D29EA6DEDA0DC7338A |
|
CONTENT
ssdeep
|
384:grwiT82bYwoMO9aFPUpaVd/rYkxDWV7FHrwukw8Cm:gciT5bT3rYkxD27VrPu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bdd6a1d52e056952 |
|
VISUAL
aHash
|
ffff00180c000201 |
|
VISUAL
dHash
|
be9cdb6338baaab3 |
|
VISUAL
wHash
|
ffff011f9e080303 |
|
VISUAL
colorHash
|
0a400030000 |
|
VISUAL
cropResistant
|
858d9bb3b9796860,e5f1f9f8fafcfefc,a2a09ab29ada80a2,be9cdb6338baaab3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 31 techniques to evade detection by security scanners and make reverse engineering more difficult.