Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F1E110E1D011ED3B436386D5A7B62B0B76D1C349CE030A5493F893AF5BDAC90DA22999 |
|
CONTENT
ssdeep
|
96:Tke9DCMdSTBEWhUSPRr8v67PjeG5a1ltWX3HFJ25XjdX/e8pYQJSjDmST5J:Qe9DDMVB8if5amaXrppJMDb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d9d87666e6c888b1 |
|
VISUAL
aHash
|
801818387c000000 |
|
VISUAL
dHash
|
0db2b2b2b20c2000 |
|
VISUAL
wHash
|
c0181818ffc70000 |
|
VISUAL
colorHash
|
160000101c0 |
|
VISUAL
cropResistant
|
2272320230300000,0db2b2b2b20c2000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 59 techniques to evade detection by security scanners and make reverse engineering more difficult.