Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T185124033AA00CD2A4E9B96CCF1C495894129D345FB3148CBB1A091FF7BC4DF0699979E |
|
CONTENT
ssdeep
|
192:Sd3U3YdIdu/GkPugswxoZMcnthWeNWbnfMmUU8VCo9:fuALefMmUFCo9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a31bdc267628d933 |
|
VISUAL
aHash
|
00383d27273f73fe |
|
VISUAL
dHash
|
ccf2f3cdcdf2c7d4 |
|
VISUAL
wHash
|
00382d27272f73fe |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
ccf2f3cdcdf2c7d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.