Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16C9394216112592B855792C4ABB92B4B71D2E34AC6630EDCF7F9436BDFCEDB0BC09250 |
|
CONTENT
ssdeep
|
1536:SbtLe44kgY9Wxy02vIBc+ZtUjsHHK9FJG9iybHqzeeeIeeeqeeeieeeiv17v1Vvl:iJ+bVm6s3F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ea7eb54955950256 |
|
VISUAL
aHash
|
01c1f1f0f0f1ffff |
|
VISUAL
dHash
|
132f23a3c3c3c38c |
|
VISUAL
wHash
|
0080e1f0e071ffff |
|
VISUAL
colorHash
|
060030000c0 |
|
VISUAL
cropResistant
|
332f2383c3c3918c,19b9bb9edccc88c8,000026d4d4462100,0c00001bebeb9b4b,6f696f16064b4f0a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 260 techniques to evade detection by security scanners and make reverse engineering more difficult.