Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FDD2F432700C6DBF7A6746AAB7E77768D39F934C84318A70C96C0A79CA86F655533083 |
|
CONTENT
ssdeep
|
384:C3mSzju+jDB59x5bUGL01OQzdL+KxoCMwn37ov1OPk+2x0Vdw/P9PXrX:C3mSzjD3x5bD4k0TeJwnlVANr |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc9633196363c9e6 |
|
VISUAL
aHash
|
2c1e3c7818183800 |
|
VISUAL
dHash
|
d8b4f0f2b0b0d0cc |
|
VISUAL
wHash
|
7c7e7e7a38183c20 |
|
VISUAL
colorHash
|
38000038000 |
|
VISUAL
cropResistant
|
d8b4f0f2b0b0d0cc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 13 techniques to evade detection by security scanners and make reverse engineering more difficult.