Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D0B2C6725184263B519783C5F762B72DA2D39388DB89181543FC4B4E8FDBF50DC2369A |
|
CONTENT
ssdeep
|
384:pugy5NrcyHG42Vq+iWy0s8KIIIIIIMi5oZw0VsQcUvEk5xmpsYQkv2IYsOy2+y9j:cgy5NrrGTgIIIIIISSOcFk5xmpPM7sOn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d62fa910d449c7d6 |
|
VISUAL
aHash
|
000120000400ffff |
|
VISUAL
dHash
|
970f4d416c8cf100 |
|
VISUAL
wHash
|
0087f5a00e04ffff |
|
VISUAL
colorHash
|
32001400200 |
|
VISUAL
cropResistant
|
8a300c4d0c300482,1080800030908000,d71f6d4950ec8cb1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.