Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F2E142E1D440DD37471286C9E7F96B4BB791C349CB470544A3F883AB9BCACA0CB15599 |
|
CONTENT
ssdeep
|
96:Tk0nbzH71tDlUG9adtMlyt7C7ythP9QwvFkQeRXuHF/edXzX/i5oJ:Q0nbzH715lUGodCly47yPP9S4sxXN |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b4b03ce4cd19c3cb |
|
VISUAL
aHash
|
c7f7ffffffff0000 |
|
VISUAL
dHash
|
1606181e080d1008 |
|
VISUAL
wHash
|
c3c3efffff000000 |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
1616081e1e040c2d,0080002020200080,0000000000000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.