Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D6F140E0D044ED3B435386D9B7B56B0BB791C389CF07194493F483AB9BCADA0CB16299 |
|
CONTENT
ssdeep
|
192:Q9MqmWlvlSlVyn8zDJ1U1yet8iIGv5xEJBC0YMn/ixy3Gaq9:Q9MqmWlvlSlVXNUyU1Zv5uTSMn/oWGaq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b4a40f9919ee469e |
|
VISUAL
aHash
|
dff7f3c7dfffff00 |
|
VISUAL
dHash
|
3226261610440000 |
|
VISUAL
wHash
|
91c30303c0f0ff00 |
|
VISUAL
colorHash
|
07601010000 |
|
VISUAL
cropResistant
|
3226260612080000,0000000000000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.