Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E2328233A600CD298DAB55C8F5C09A89525ED349FB3248C6A1B050FF7BC4DF069E939D |
|
CONTENT
ssdeep
|
192:dBCMYc7c1chVO64KD/4xbHUMcnthWeNWbhKsI1CfMmUU8VCoAL:ec7c1chV/4KwVKsI1CfMmUFCoAL |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a7f307d98a07aa0d |
|
VISUAL
aHash
|
ffffffffffff0000 |
|
VISUAL
dHash
|
cc0c8c0c00096267 |
|
VISUAL
wHash
|
67e7e7efff000000 |
|
VISUAL
colorHash
|
0f001000090 |
|
VISUAL
cropResistant
|
cc0d880c0c000804,0f0d7256e6761d1f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.