Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FF92B432A161EE37416786E6B7E8971A22D2C289CD420605D3EC83FD07FEC94FE22941 |
|
CONTENT
ssdeep
|
192:DEnxrcfp3aIr/k5erClXzRYyPzPefnVckchE6TIPTc4JZw+AIIIXiQVk381zJwQ3:DEnxwfwlX9Yh/JV6M7BeXIIIhfCIPwQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92966d3d31691e4d |
|
VISUAL
aHash
|
027e7e0e0e0e0000 |
|
VISUAL
dHash
|
8ccccccccc2cd2cd |
|
VISUAL
wHash
|
46ff7e6e0e0e003c |
|
VISUAL
colorHash
|
31007000000 |
|
VISUAL
cropResistant
|
76664e6662de0ed3,8ccccccccc2cd2cd |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 35 techniques to evade detection by security scanners and make reverse engineering more difficult.