Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12B631F31A940DC2701C7C6C463B22B6E62A9C315C6130AD9FBF483A95FDBCACDE76255 |
|
CONTENT
ssdeep
|
1536:vt+23oTwlqWqzNvvvvfduP4agsIxt479F:1+23oTwlqWqZdu/gx47T |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ad4f701b295e7624 |
|
VISUAL
aHash
|
01fb233303efd7c3 |
|
VISUAL
dHash
|
abb26763cb4fafae |
|
VISUAL
wHash
|
007ba31303efd7c3 |
|
VISUAL
colorHash
|
07601000040 |
|
VISUAL
cropResistant
|
aba267e3cb0fafae,2baab3666723cbe3,8c978191d115273f,2416160e0c0c0d0e,87cfcedcd0f09399,80849412470f7c64 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 95 techniques to evade detection by security scanners and make reverse engineering more difficult.