Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T194322E766408A93756C7C1E15B72BB5FA3A4D299CB031B4263F8C39D4BC1CE2DC32295 |
|
CONTENT
ssdeep
|
192:XwwKjqKiKO4/ic3G1YE3ZjSFTfOiAfWTOAjp6foR3l6fMBoVBpY5fM+CDizp4:Xwt7HO7c3AYujK1YtYKDizp4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
996634396f96b491 |
|
VISUAL
aHash
|
00007e38381c1c1c |
|
VISUAL
dHash
|
0bc4c4e072593110 |
|
VISUAL
wHash
|
00007e3c3c3cfcff |
|
VISUAL
colorHash
|
30003000180 |
|
VISUAL
cropResistant
|
b21a198dc37060b0,0bc4c4e072593110 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.