Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1403245E0C194AA3A435742D8F7B9AB5773B1C2C4CF06094853F4879EAFCEEA0CE61559 |
|
CONTENT
ssdeep
|
192:Q4cYGBkreQnelw/gRc8V5uks8iILdnaP0YzrndZIw:Q1/BkreH4ks10Na8SnzIw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b099cdc7c730cc33 |
|
VISUAL
aHash
|
ffc7c7c3e7f7c7df |
|
VISUAL
dHash
|
481c14150c040c14 |
|
VISUAL
wHash
|
a7c3c3c3c0c0c084 |
|
VISUAL
colorHash
|
070000100c0 |
|
VISUAL
cropResistant
|
481c14150c040c14 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 61 techniques to evade detection by security scanners and make reverse engineering more difficult.