Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C0A2C732A140263F625783DCB721F31DE1E39249EB550C15A3FC4B6D8BD7E51CA638AA |
|
CONTENT
ssdeep
|
384:iiqy5NBT+kcVviQnQ4dbIIIIIkeG7tJ0JjJp//V0VaM4kBoiIYsOy2+y9BH4cCUl:Vqy5NBPctIIIIIC3ejLHV0VT4kn7sOyK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b83ac3e9c7926938 |
|
VISUAL
aHash
|
f9848e8f91f1fffe |
|
VISUAL
dHash
|
633c3c3c33b3c890 |
|
VISUAL
wHash
|
b084040f0b71fffe |
|
VISUAL
colorHash
|
07001000180 |
|
VISUAL
cropResistant
|
633c3c3c33b3c890 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.