Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AB73427552E9467F943383C4BA667F2971E1A25DEA424943A3FD032A27DECCB7C43824 |
|
CONTENT
ssdeep
|
1536:sJdIIaiz+srG3eU80faB5f2WG08jC8GHq:2GA9Hq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
eea5909a9d62136d |
|
VISUAL
aHash
|
fff3e1e1b1f1f1ff |
|
VISUAL
dHash
|
7007472763692525 |
|
VISUAL
wHash
|
3ee1a181a181f1ff |
|
VISUAL
colorHash
|
06401000040 |
|
VISUAL
cropResistant
|
7007472763692525,0e636353152721bd,9b090d89dd64487f,715950e101ddecf6,036361315b136420,0e5f6f591f0f4e22 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.