Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11F741AB2A225617D014346D65A3A73A8A3A7934ADAC002D453EC93FCE7CFDD4E9673C4 |
|
CONTENT
ssdeep
|
3072:0FQcWKmPGSF/O+lbEexE/m9LhFyr1B0lNDtnKwZ1LnpxE9MDc5aADzzYlht:0FqKqjlEexI1B0lNDU+Ayht |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc1bc319184f663e |
|
VISUAL
aHash
|
7fff939383c3f7f3 |
|
VISUAL
dHash
|
c83e273737272727 |
|
VISUAL
wHash
|
00ff9383878387f3 |
|
VISUAL
colorHash
|
072010000c0 |
|
VISUAL
cropResistant
|
d836273737272727,0000000000000000,677367e7e3676161,ebe347664b539555,8dccce8dcc6b484c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 798 techniques to evade detection by security scanners and make reverse engineering more difficult.