Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T113233D7280C0753D07E205C2E7527F88D3D64046C7667BC7A3BF862C9FD6958ADB22A9 |
|
CONTENT
ssdeep
|
768:ozRT/8zBVQFO8jV/h5a6TeXbzblH2Fa5gxursLKR8Mst:ozRT/8jQfRpE6iXHblWF2gxu4mypt |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cf6361cd8663ccc2 |
|
VISUAL
aHash
|
6000003c3c38201c |
|
VISUAL
dHash
|
c4d1d0696172ccf0 |
|
VISUAL
wHash
|
72783c3c3c3c3c3c |
|
VISUAL
colorHash
|
000000001c0 |
|
VISUAL
cropResistant
|
3333194c4c556c2c,3737273e2424a4a4,c4d1d0696172ccf0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 932 techniques to evade detection by security scanners and make reverse engineering more difficult.