Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T163139331BA00EE2641CB4AC8A273566963FA8345D25216D8FEB1C3F95B9FC7DCA33454 |
|
CONTENT
ssdeep
|
768:tsIx/j2RZ/Z+a8zgvDBOxfp59NjTHWOpbfYqMsDUf79/gH+K0Pm:tsIx6RZhp8zgbBOXpbfYx79/pm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed4c130e656c33ce |
|
VISUAL
aHash
|
00fefbd3f3dfffef |
|
VISUAL
dHash
|
ccd21212a738339c |
|
VISUAL
wHash
|
003acac31107ffef |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
d21212a73f33319e,048cdbd82418c5c0,96868e963331b1b1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 110 techniques to evade detection by security scanners and make reverse engineering more difficult.