Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10202A47111300A3EA45787A0F1507F39F19EE388DF6B78ADB22CC5761A9AC78CA8D950 |
|
CONTENT
ssdeep
|
192:lS5AMAvA3AgAnAyZunLISBrJGy9mdbpvdIOnsbKeEx5oaHHFz1cgv5NN:8KzoQHA8unLISBA4bNETFhFT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f68c8c6633993366 |
|
VISUAL
aHash
|
ffffffffe6e4f8e0 |
|
VISUAL
dHash
|
002408324d4c320c |
|
VISUAL
wHash
|
fffee8f8e0c0c080 |
|
VISUAL
colorHash
|
07000000190 |
|
VISUAL
cropResistant
|
002408324d4c320c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 49 techniques to evade detection by security scanners and make reverse engineering more difficult.