Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19BE35D703244797D2B7343EA30A53506B279D21AD45F8820F358E5B927EAD9AF4277CC |
|
CONTENT
ssdeep
|
3072:+1Y1o141T51fi1e1jAeK1e1h101VpXjUMAL98n0d0++M:+1Y1o141T51fi1e1jAeK1e1h101Dz45l |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3469cc86332e63e |
|
VISUAL
aHash
|
801aa3e7efff8f8f |
|
VISUAL
dHash
|
29724dccc8c4183b |
|
VISUAL
wHash
|
0000a2e7e77f8f8f |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
29724dccc8c4183b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.