Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DD733F33E5C9387F0112F08AE805BF0975DA407FDFAA066293FC6EAF26D3D609665149 |
|
CONTENT
ssdeep
|
768:TeToE3AnkdDXc0csjNu0x9fSqyJl9jaLJysafPpYiUCb+hZtARyZnh77UL9Iwvb7:TCnHlXc0csRuU9fSq0F2PCcARnUG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bcc719664f31073c |
|
VISUAL
aHash
|
00ff87ff93c1c38f |
|
VISUAL
dHash
|
63042e2727271733 |
|
VISUAL
wHash
|
00ff83ff81c1838f |
|
VISUAL
colorHash
|
07200180001 |
|
VISUAL
cropResistant
|
63272e2727071733,00200c7230380420,181d7571385d333e,9b93932b53d3b5f9,00802394a0a451a4,811b13543c240780 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 31 techniques to evade detection by security scanners and make reverse engineering more difficult.