Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17BD2FA21A904EC6641DF99C89672566672FA8384C2130698FEB4C3FA5BEFC7CCB77144 |
|
CONTENT
ssdeep
|
384:TbEDuVN4gBotudWtsqGKpRk+P7MIcqFsJO5xVZjqTSnIroUa879ft:ToDuIgBo/sqGKpRkIcqFsIx/jXUf79F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
804ad1399ddf50bb |
|
VISUAL
aHash
|
000000000000ffff |
|
VISUAL
dHash
|
c1eda960db8e2ece |
|
VISUAL
wHash
|
7171703001c0ffff |
|
VISUAL
colorHash
|
12007000000 |
|
VISUAL
cropResistant
|
0009b24ccdf2c282,c2edada964fb8fae |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.