Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D692A7B354D8AC136E34C9CDBDE1B71DA9A2C0DADA178CCDE1D8528E36C5DE2D583221 |
|
CONTENT
ssdeep
|
384:eHgJ3JhX3kiPu5CJPSh36x15hhOKuq1sLZS21IJ4DU+Gh42Bq7a+zKy0f:hJ3JhXO5CJPShKxfhMKuqUo21IqDU+Gh |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
992433ccc9b3e4b3 |
|
VISUAL
aHash
|
1810001899bdbd3d |
|
VISUAL
dHash
|
e8202b3b2bb2797b |
|
VISUAL
wHash
|
1800081899fffffc |
|
VISUAL
colorHash
|
06441008000 |
|
VISUAL
cropResistant
|
293d35cc8eba1a1a,8d8d95be4d3dbd39,e8202b3b2bb2797b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 24 techniques to evade detection by security scanners and make reverse engineering more difficult.