Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12F04FF73154D889A2255A3C1C3B0F65BB640CA0BDF329ED4D3A54BCDD9E4F00FA72A99 |
|
CONTENT
ssdeep
|
1536:c9XkEZI9vbehuNod4olZvCtW3V/vyegr64ggLNI:vEmWFZvC4vy44jLNI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8d9460da7f8983a7 |
|
VISUAL
aHash
|
00407fdbbf7c0000 |
|
VISUAL
dHash
|
71b6e23264e90707 |
|
VISUAL
wHash
|
1c427fff9b7f0000 |
|
VISUAL
colorHash
|
08000000180 |
|
VISUAL
cropResistant
|
5a73cec3688e3210,535364342a6e5353,54f6383128b0981c,8080303232100092,71b6e23264e90707 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 963 techniques to evade detection by security scanners and make reverse engineering more difficult.