Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T183834CF0A980FE2242B340D2706F8646F3BE491BAC1E4890F79CC6D773EA86715676D5 |
|
CONTENT
ssdeep
|
768:oT0TQH7anYFUxQGMaO2MoAA/yh1tHT77mSRVNTv33CDgMES2++LwsIAOyaaVV9Bm:fPpD4Cw6Z+lBI/XfKzQ2N0msQw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
933ce996bc313097 |
|
VISUAL
aHash
|
002808003e2c7eff |
|
VISUAL
dHash
|
9cc8c9dcecdcd0d0 |
|
VISUAL
wHash
|
003c2c003e7e7eff |
|
VISUAL
colorHash
|
38000010002 |
|
VISUAL
cropResistant
|
ccdc9edcccc48ee8,4866b6b3a3b2b294,9cc8c9dcecdcd0d0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 36 techniques to evade detection by security scanners and make reverse engineering more difficult.