Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T128A19617A20C337016A740D9EFA606F5A730A84073D5269C66ED416C06D5ADCA3F7FDE |
|
CONTENT
ssdeep
|
96:TzjYn9nrGF2CfTsu++bnloH940wJRiqp9LNdLi+mL2T:7GnyF2C1bloH940ipRNdW+n |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8f183066366733cf |
|
VISUAL
aHash
|
01193d3931393b3f |
|
VISUAL
dHash
|
6b73796363636373 |
|
VISUAL
wHash
|
013d3d3d313d313b |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
6b73796363636373 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.