Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T151430EB18343443BA56791C8ED695B0B9297A30FD7020E48B3FA467ADFCED24BC562D1 |
|
CONTENT
ssdeep
|
768:Ud3F+q1upxzWy2OE3/UVhzdOlHZ7viJBJBse+fZHzaDbcduhsty0gKIBKen8QT/1:UdN1sxzWy2OE3/UVhhOlig6F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
956afb34e13ad221 |
|
VISUAL
aHash
|
8f000002660602ff |
|
VISUAL
dHash
|
3ccec1d6d4dc3e92 |
|
VISUAL
wHash
|
ff300216670e06ff |
|
VISUAL
colorHash
|
33600030000 |
|
VISUAL
cropResistant
|
000000808000003c,b8f8e896a2a4f0f0,80008080a0a08040,3ccaf1d4d4dc3e82 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 141 techniques to evade detection by security scanners and make reverse engineering more difficult.