Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T128D2B8FAB19369FF6593C7B9B1B0F72D618CF19DD633860496F407A11ACAEB59C02204 |
|
CONTENT
ssdeep
|
768:SpSQCzPEvGTXUVTqw7SI9b98YOZ5zRuYJ:KIKR7L9b987bIq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9095b4b6b6b63694 |
|
VISUAL
aHash
|
4e785c007e007e00 |
|
VISUAL
dHash
|
9cd3d0b0d4d4d4a8 |
|
VISUAL
wHash
|
ff785e007e007e54 |
|
VISUAL
colorHash
|
32602008000 |
|
VISUAL
cropResistant
|
9cd3d0b0d4d4d4a8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 19 techniques to evade detection by security scanners and make reverse engineering more difficult.