Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16C73A5F18248F4A20587C3F9EB39176B729AD0EEDB970A4943F48798EED1DD2DC01A54 |
|
CONTENT
ssdeep
|
768:7bexHeChRZLRZORZxRZ9/OKinknsc39B7QEoMf:2eChRdRgRDRH/OKinknJmMf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
95857e3f31cd85c0 |
|
VISUAL
aHash
|
07077f0f07078fd8 |
|
VISUAL
dHash
|
7ebcc6de9e3eb232 |
|
VISUAL
wHash
|
07077f0f47079fc0 |
|
VISUAL
colorHash
|
10400038000 |
|
VISUAL
cropResistant
|
7ebcc6de9e3eb232 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.