Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13EF23130A280697B0293C2CCE7715F6BA3D0C285CA270A4F62F4875DDF9FE55DE66609 |
|
CONTENT
ssdeep
|
768:YQ/cbfLeeeKeeefeeeTb5mTACa/JxHF8Wju:1UfLeeeKeeefeeeTb5mTACa/JxHF8Wju |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9d9535358d956439 |
|
VISUAL
aHash
|
6618183c3c180818 |
|
VISUAL
dHash
|
d6f0f070f0f171b2 |
|
VISUAL
wHash
|
7e183c3c3c3c1c5e |
|
VISUAL
colorHash
|
381c0000000 |
|
VISUAL
cropResistant
|
d6f0f070f0f171b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 13 techniques to evade detection by security scanners and make reverse engineering more difficult.