Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F1D2717360A5B877659382D26134B34FB391FD8DABC3BA15D6F887462FC2DD9D810A80 |
|
CONTENT
ssdeep
|
768:25lELEYEppFU5l4w3pjNKXeU1DT5M0omICf+beqKfoeeiSb0Rz7HY:2vELcp+GyludN/ojMg1wkR45Y |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92cd93a699a699a6 |
|
VISUAL
aHash
|
ff0000000024240c |
|
VISUAL
dHash
|
f2328c542a4d4daa |
|
VISUAL
wHash
|
ff180000006666ff |
|
VISUAL
colorHash
|
00000038000 |
|
VISUAL
cropResistant
|
00c0c0c0d0d00000,e4e8c28605c5e6f0,0216067676161606,323008040a4d4daa |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 46 techniques to evade detection by security scanners and make reverse engineering more difficult.