Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A73384F3D1F9497613A353E43A2076CDF99A820ECA8140E5A6A8C35C97D5EF1F60325E |
|
CONTENT
ssdeep
|
1536:Q+giVg4IVPl7vWFhxFe2N1RAbsvoWnjIpIzcQR3YS5peX8HFBzNiGEEpuSbcsFTp:Q+giVg4IVt7vWFhxFe2N1RAbsvoWnjIM |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f3aa538a584acb72 |
|
VISUAL
aHash
|
fde7e7c3d7e3c3c2 |
|
VISUAL
dHash
|
790c0d3737060e1e |
|
VISUAL
wHash
|
81c3e781dfc3c3c8 |
|
VISUAL
colorHash
|
07000038000 |
|
VISUAL
cropResistant
|
790c0d3737060e1e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 292 techniques to evade detection by security scanners and make reverse engineering more difficult.