Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AAE132E1C018DD36036246D5F7F56B5FBAD6C349CF02098453F882AB9BDAC70CA62699 |
|
CONTENT
ssdeep
|
96:Tk8NszHkhOhHW0eGUEdt7XZIrwvl/eFX3HlOe8sXY24/2t7rfQsR:QhHkhOhHWsUEdNZCV38T24+hfQ6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e66666999999998a |
|
VISUAL
aHash
|
ffc3e7ffffffef00 |
|
VISUAL
dHash
|
140e0c300c0e0c20 |
|
VISUAL
wHash
|
fcc0000c87c3e700 |
|
VISUAL
colorHash
|
07030000200 |
|
VISUAL
cropResistant
|
140e0c300c0e0c20,418a259a9a248041 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.