Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A2D31F16BF51982568770AF5D1703652A064F6CFCE47E0D0F35EA9B0DE9E8732F2029A |
|
CONTENT
ssdeep
|
1536:5eze+e9LDIcULQTMzuT9138oV87Z38NURWrOa5wa71fpHUVKoBPLS:JLDBULCMMd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bbce31c4d415cd51 |
|
VISUAL
aHash
|
fff1bd9ff1e187c5 |
|
VISUAL
dHash
|
86237b694b0b1e19 |
|
VISUAL
wHash
|
fee1998fe1c18384 |
|
VISUAL
colorHash
|
07008200201 |
|
VISUAL
cropResistant
|
86237b694b0b1e19,a200a0490001d0f0,49ccd05ad1f4d44a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.