Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B26373307560987600DFE6C9A6755B1A22F2D306CA0306DEF6F4C3F58BCED68DA63259 |
|
CONTENT
ssdeep
|
768:HUf72+LsIx/jp42SQ9xVUy9a/8z9P2l7cLV32opF:472+LsIxm2SQVUsa8d2l4RGopF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cdd5b5d4c1c43a32 |
|
VISUAL
aHash
|
ffff003800101001 |
|
VISUAL
dHash
|
c6e8f9d0e0246573 |
|
VISUAL
wHash
|
ffff387870101099 |
|
VISUAL
colorHash
|
00006000000 |
|
VISUAL
cropResistant
|
92000862628800b0,c6e8f9d0e0246573 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 78 techniques to evade detection by security scanners and make reverse engineering more difficult.