Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18C1466F0235415EA4AC3FBD0D5A33E57657689FAF21F9ECC52B848482EC1E99C4C96E0 |
|
CONTENT
ssdeep
|
1536:gGzG5HHHN9Yv7zUm7fj2DI0E1U+7MW7Tx76v7YX7UDUVU/PEbAyvf6Pidpkk/Ksv:7q5HHHA7zUUfj2DI0E1Ha/MMb8uTxK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e896976968c67896 |
|
VISUAL
aHash
|
ffdfd1d1c1c1ffff |
|
VISUAL
dHash
|
6338352383933825 |
|
VISUAL
wHash
|
ff9f80800101bfef |
|
VISUAL
colorHash
|
07030000600 |
|
VISUAL
cropResistant
|
6338352383933825,800890860e969068,69794d6971865831 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 104732 techniques to evade detection by security scanners and make reverse engineering more difficult.