Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DB51A5F2E1697C14126343B79D8125799163132FC1630A8AB3FC52CA3BD2DEC86132C8 |
|
CONTENT
ssdeep
|
48:gURrKx9UKxDKxhiHJ9vJ9xAJqcD7AMCAn1Xw3QnFBpu:gUBKEKZK3G5TxzcAJK1Xw3mFnu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a020de8c6dcfcd2b |
|
VISUAL
aHash
|
67474703030fffff |
|
VISUAL
dHash
|
8e8ecececed6d84e |
|
VISUAL
wHash
|
670703030303ffff |
|
VISUAL
colorHash
|
06e00000000 |
|
VISUAL
cropResistant
|
8e8ecececed6d84e,dc7d6c6d6b65f166,838383736c5c5838,0e0e070707030313,1018181c1c1c1c1e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 32 techniques to evade detection by security scanners and make reverse engineering more difficult.