Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T140433F31A404ED3701DB49D8A63A435A62FA8345C6530689FAF8C3F95BDFC69DE37148 |
|
CONTENT
ssdeep
|
1536:dsIxKOTB4doFRQFRsFRt1wiYSj37UTMv1zv:dcdaRyRORt1wiYSj37SMNzv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d318e71866a956e9 |
|
VISUAL
aHash
|
000c0000000cfff7 |
|
VISUAL
dHash
|
d8f8cad8d8b0030e |
|
VISUAL
wHash
|
001e3e2e0c08ffff |
|
VISUAL
colorHash
|
0e2010001c0 |
|
VISUAL
cropResistant
|
08000b0b0b0e0e0e,d0a335cdcdcdd5cd,dcf8b8cadad8d0b8,0000041a32b232cc,00c003e0d4e8e8cc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 93 techniques to evade detection by security scanners and make reverse engineering more difficult.