Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T154733332D3531913A07BC5D8F07247892291868DC7174B79B7BD63BAF9CECB63612298 |
|
CONTENT
ssdeep
|
1536:uSpLzo6XeAeueAIZrccW57rYxpTTp0Iebeetd7UOshH6ueQGee0t9eeH6RLpTxAX:vN57rYxpJzOkaOXKsGq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b86c67c6939894c7 |
|
VISUAL
aHash
|
8181c3cff7c7cfc7 |
|
VISUAL
dHash
|
2b2337900f1d1f9f |
|
VISUAL
wHash
|
818181cfc7c7c7c7 |
|
VISUAL
colorHash
|
06000030000 |
|
VISUAL
cropResistant
|
2b2337900f1d1f9f,717924f035372b2b,e3696c646c6c2c2d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.