Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T181829632B24315BF117B4AE6F1B4A765F092C70ECA278465A3FD83A72BC7C52A991304 |
|
CONTENT
ssdeep
|
192:gM1r9TCSENBWu7vRqw4Tkt459qPotumy1q/nqVgSDQw7RO7yOg:ySYWnw4ItleBTSDTr |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9312ec6ce9e06ce5 |
|
VISUAL
aHash
|
000e0e0e0400ffff |
|
VISUAL
dHash
|
831c5c5c58270c0c |
|
VISUAL
wHash
|
c00e0e0e0e03ffff |
|
VISUAL
colorHash
|
020000001c0 |
|
VISUAL
cropResistant
|
f03cedf099c87171,100c618e964d0c16,831c5c5c5c581c06 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 34 techniques to evade detection by security scanners and make reverse engineering more difficult.