Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T185A3BB27412935274537C2C130796B3FD1A6998BFEE70A014EDCCBEA6BF9CA0745B129 |
|
CONTENT
ssdeep
|
768:JUtpR4nXF6YjOpSpFlTC6rrnWyl7ApfpqX:JUtpR4nXBKpSpFl26vll0pBqX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d212ad6db8134bc7 |
|
VISUAL
aHash
|
00002c0c0000ffff |
|
VISUAL
dHash
|
16e4c9c9c8808024 |
|
VISUAL
wHash
|
00243c3c7c20ffff |
|
VISUAL
colorHash
|
32007000000 |
|
VISUAL
cropResistant
|
0000006068600040,000000c040c00040,000000b034300020,0000a0c0a0a00000,8002d82426162666,02e4c8e9c9c8c080 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 113 techniques to evade detection by security scanners and make reverse engineering more difficult.