Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CE7265B1C162397B91F389F6F2556F3D91DDA298EB078063B2BC02154FEAC847A57740 |
|
CONTENT
ssdeep
|
192:7m+PYNplbBXkbAgMNfZVjELSHi0jSBpbE333333333333333333350THdceuTDjO:7XPYNpdBXkEgwfZV+mXgpbQUceoM |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c2c63d39319ec6c3 |
|
VISUAL
aHash
|
40e0f6fe64000000 |
|
VISUAL
dHash
|
9c8bccccdc8d2388 |
|
VISUAL
wHash
|
e0e4ffffef002100 |
|
VISUAL
colorHash
|
38000000188 |
|
VISUAL
cropResistant
|
9c8bccccdc8d2388 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 28 techniques to evade detection by security scanners and make reverse engineering more difficult.