Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18EF276B232210EAE90D7DBB0F3227F76609A8398D957536EB1ED82741FC5C51DC9A780 |
|
CONTENT
ssdeep
|
384:G5ybvmFWaWSWzWhWnWV1qiqJdLULvyj0xRUewkQ+3Zx81auN8e6cQ/TXwyLrTunA:ldLULj2S611JQ/rBMrmlvPVFR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8cca33a3ec8d8b8b |
|
VISUAL
aHash
|
ff2c3c3838181000 |
|
VISUAL
dHash
|
43cc713020726a70 |
|
VISUAL
wHash
|
ff3c3c183c183f18 |
|
VISUAL
colorHash
|
38001400010 |
|
VISUAL
cropResistant
|
43cc713020726a70 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 43 techniques to evade detection by security scanners and make reverse engineering more difficult.