Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FF932A7181412A7B624353D97225669A76F2112AF713C64CC2F95B2EAF81CC6CC378BF |
|
CONTENT
ssdeep
|
1536:Q32M361ahKfoOBF3C91kz+zr29qSnmdyLIQRZPKh4KJfzjeL5TNnqgeMm:Q3xxYtMg5TNnqsm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e262b83766b038f6 |
|
VISUAL
aHash
|
806040202000ffff |
|
VISUAL
dHash
|
04c1818a48a4d8b2 |
|
VISUAL
wHash
|
e060e060e0e0ffff |
|
VISUAL
colorHash
|
1a600018000 |
|
VISUAL
cropResistant
|
c9cd92b29193a3a3,fffefefcbcf95062,316960d0c0808000,d2d1c18480c08080,004000001032a737,04c1c183a2ca08a0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 28 techniques to evade detection by security scanners and make reverse engineering more difficult.