Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14E221A31A3045639E6DE8380C7B66D163369509AE708491CC7E17A76EEB3DEE6C045EC |
|
CONTENT
ssdeep
|
192:ZETCTIyjjw7Vni5Iz9eF+vYx3dEmJnERAE88Qs6L21gtOpBHKmAJW8xi2hYBtKP:thUimgx3dEnAEfV6L2il8Ki2hYBtKP |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b366666666666433 |
|
VISUAL
aHash
|
e7e7e7e7e7e7e7e7 |
|
VISUAL
dHash
|
4d4d4c0c4c0c4c0c |
|
VISUAL
wHash
|
2727272727272727 |
|
VISUAL
colorHash
|
07000030000 |
|
VISUAL
cropResistant
|
4d4d4c0c4c0c4c0c,00a29b9c0c0ac2a4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 18 techniques to evade detection by security scanners and make reverse engineering more difficult.