Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FD326133A600CD2E8D979188F5C0958C9559C386FB3148CAB1A090FF7BC5DF169A97AE |
|
CONTENT
ssdeep
|
192:/pVnIuK14W/Ud/JxL6QMcnthWeNWbnfMmUU8VCo4:9K14WcdD+fMmUFCo4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e96915b6b6267298 |
|
VISUAL
aHash
|
00000000ffffffff |
|
VISUAL
dHash
|
ce9296cf00000000 |
|
VISUAL
wHash
|
00000000ffffffff |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
c0a0e0f0a0c8b2b2,4400000000000000,8e96869292968fc7 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.