Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DE0387B25243453FDA4BC2CAFB696B4DA2C6936BC2620D41B7F1471BDF82E64FC15160 |
|
CONTENT
ssdeep
|
768:7/dKNrzGNt9Zs+GPTnZwbbQNKhrp+ohCyoxaSrE0X1Xmh2fld1ClthJu/fi0n+mp:Dzs0C4/KzLF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93936c349e11c9d7 |
|
VISUAL
aHash
|
0c006c2cbe240081 |
|
VISUAL
dHash
|
a9c6d8d84cdcd231 |
|
VISUAL
wHash
|
1c607e7efe6e4081 |
|
VISUAL
colorHash
|
300010000c0 |
|
VISUAL
cropResistant
|
000000904465a6e8,f09119f3d3195939,78e9e4f6de3673f3,a9c6d8d84cdcd231 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 151 techniques to evade detection by security scanners and make reverse engineering more difficult.