Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DB24A7B0629068EB9057C7D4F121BD7FF05773BFBA0EC14452F89A449FD689C780A8A9 |
|
CONTENT
ssdeep
|
1536:h8ANd8P8PcMr/MuwWzZ0ueE++6Pc/Xy8ksKhY6cVR+GQT:4rdcnE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cf26ddb132649a98 |
|
VISUAL
aHash
|
003818001cffffff |
|
VISUAL
dHash
|
3069614f79717271 |
|
VISUAL
wHash
|
001818003cffffff |
|
VISUAL
colorHash
|
01010000e00 |
|
VISUAL
cropResistant
|
3069614f79717271,969c8b29694ab4cb |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 77 techniques to evade detection by security scanners and make reverse engineering more difficult.