Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EBE284777158203B932384C930F2BB4DB3EB918DDB0345AD93BC02E65BD7C9494766A9 |
|
CONTENT
ssdeep
|
384:lCnlUs/1dUl6egDSV2TnzcungCjKdYC+c+Jl4blYqyxKB2NYTyXJMlsmlOeF:lCnlUs/o9CjKJxy4BtifJIs2OeF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
be6ec43e95916ac0 |
|
VISUAL
aHash
|
818181878181ffff |
|
VISUAL
dHash
|
2525511f1d3d0d08 |
|
VISUAL
wHash
|
8181818f8581ffff |
|
VISUAL
colorHash
|
1b401008400 |
|
VISUAL
cropResistant
|
2525511f1d3d0d08,1515565555b4332b,d5d41a5a5a1a1ad5,a6a6a6b59d9c1ccc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 28 techniques to evade detection by security scanners and make reverse engineering more difficult.