Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T142223073A600DD2A4D9B6688F2C49588415EC345FB3148C7B1B491FF7BC4EF069A93AE |
|
CONTENT
ssdeep
|
192:8l3JIdDV2Q4l4et8uxwzMcnthWeNWbZfMmUU8VCob4:jR2Q4l4defMmUFCob4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9d41e3378959aa33 |
|
VISUAL
aHash
|
00309e9a061e04ff |
|
VISUAL
dHash
|
cee43032743c7cc1 |
|
VISUAL
wHash
|
007c9e9e060e1eff |
|
VISUAL
colorHash
|
072000001c0 |
|
VISUAL
cropResistant
|
39199a23ccd4969a,c2b2b0cac2b0b2ca,c989c9a985000000,cee43032743c7cc9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.