Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18D82ECE1C151F93B436782C6A7723B1B76E1C388DF170A54A3F8936B5BC9C90DA2249D |
|
CONTENT
ssdeep
|
384:+oGTfZvnCd1SYO8eduyxoS2lFNuM72yD3QqLUbm3OEooixpy8F:+jTfRCd1SYO8edZxoS2lFoW2yD3QqLUD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b907e6f443b8c4c9 |
|
VISUAL
aHash
|
07070b010bffdfff |
|
VISUAL
dHash
|
2e6e723bbb343ed6 |
|
VISUAL
wHash
|
0703030109dfdfff |
|
VISUAL
colorHash
|
06006000000 |
|
VISUAL
cropResistant
|
2e6e723bbb343ed6,0405353737338fc7,0e1e7c6f634b5343,7e3f5679bb199d3b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 31 techniques to evade detection by security scanners and make reverse engineering more difficult.