Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CF533030B904DD2B01CB5AD56232435A72EA8385C61316C8FAF9C3F91BEFD69DA37158 |
|
CONTENT
ssdeep
|
1536:wUosIx34xBXmEFoVFonFoouaRj0sS+TMH7Zp7zzJ:IEm2oPoFo8Rj0sSoMH7D7zzJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c112ed1ae58e65ae |
|
VISUAL
aHash
|
000c08000000fffb |
|
VISUAL
dHash
|
dcd8d8cad8b00b02 |
|
VISUAL
wHash
|
ff0e1c0a0800fffb |
|
VISUAL
colorHash
|
0e2010001c0 |
|
VISUAL
cropResistant
|
8080808080808000,90000b4b0b0a8283,dcf8b8cadad8d0b8,0000100c32b2b232,0000000c1232b2b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 180 techniques to evade detection by security scanners and make reverse engineering more difficult.