Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T102956D23D3231809657A88D9F1779B9A2185064DE20A0F70BBADC77E7DCF47239247DA |
|
CONTENT
ssdeep
|
6144:bSPSadB50nYemKcZnB15iOROVT52IF8oK3L21MqyPEhgVscifpPE0cMA:bSPSNK3L21MqyPEyscifpPE0zA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cd6db3313899cd21 |
|
VISUAL
aHash
|
c3c3dbdbdbdaffe7 |
|
VISUAL
dHash
|
9286b2b2b2b22a2a |
|
VISUAL
wHash
|
03031b1bdbdac2c3 |
|
VISUAL
colorHash
|
07200018000 |
|
VISUAL
cropResistant
|
2b3486b2aeabaaaa,9286b2b2b2b22a2a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 49 techniques to evade detection by security scanners and make reverse engineering more difficult.