Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T101242B30330D397EE6530BA9F26672127278411BEF1F8664E77ED5362696CC6A437E80 |
|
CONTENT
ssdeep
|
1536:pUcZzXTTfhch0T5CaI3XV2FsMMXje2iqH7WKy6P204EQeje2iqH7uCp3R9uldcQt:ycZjTOTvcQ3TjzmN6/btZ92mR2j |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c13f3ce1c1b03c4f |
|
VISUAL
aHash
|
4300006e7afac000 |
|
VISUAL
dHash
|
b24139c8ca8a8840 |
|
VISUAL
wHash
|
c30004eefeff7e00 |
|
VISUAL
colorHash
|
38180008000 |
|
VISUAL
cropResistant
|
b24139c8ca8a8840 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 24 techniques to evade detection by security scanners and make reverse engineering more difficult.