Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14BD382D55618038CA15BCABDEF2FFE05131FB1AABA548680294EC268D5CF8D2F71752C |
|
CONTENT
ssdeep
|
1536:9t0RQ7Hw7uzrPahW/r/OlFsR8MLqcz5FsR8MLqcM00:r0RQ7HeiaQPYY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
abbc92f105c44bd3 |
|
VISUAL
aHash
|
ff8181838181ff00 |
|
VISUAL
dHash
|
272f2b230b0b27d5 |
|
VISUAL
wHash
|
ff838383c3c1ff00 |
|
VISUAL
colorHash
|
16000000038 |
|
VISUAL
cropResistant
|
27272b2b270b2b80,62b4d4cde189ad4d,0001081515151510 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 148 techniques to evade detection by security scanners and make reverse engineering more difficult.