Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14FB43AD1C2E15E7D7D8B8AEAFF21AB20718B90BFF6D60446A3898B9915D7C40F34D850 |
|
CONTENT
ssdeep
|
3072:xBSf3m/dJS3mxDj9UrRLvsEK62SEHhrgiGCIG5/6VVR8D0Knk6Rg8cQ7lo7mao1r:xBSfvKAL0Emhn/sR8D0Knkm7lo7maw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc93cf39c0e46992 |
|
VISUAL
aHash
|
ff9ff7d79f818391 |
|
VISUAL
dHash
|
332a262438332727 |
|
VISUAL
wHash
|
df9383978f818391 |
|
VISUAL
colorHash
|
07200088080 |
|
VISUAL
cropResistant
|
332a262438332727 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.