Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DDF100A5C541252703A358D770B1974971CBC10DCA063D986BB9A3E7EECED50384B7AF |
|
CONTENT
ssdeep
|
192:BbOYlR/Jo742OsdFWj1NsdFylH3f922MPZtmWMG1KZ3npJAX1dtCqPCqC:8UMao7fp1kXpJGw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c74eb3b349484ad9 |
|
VISUAL
aHash
|
00ff1010f8e7efef |
|
VISUAL
dHash
|
332ce0e0224f9e59 |
|
VISUAL
wHash
|
00ff1000d8e7cfef |
|
VISUAL
colorHash
|
0f000000007 |
|
VISUAL
cropResistant
|
2ca0e0224b8e9ad9,2494a6b64c29a6cc,202121447070047d,07132b2959382465,60c152d2dd163e92,09b5bd3796d35927 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 108 techniques to evade detection by security scanners and make reverse engineering more difficult.