Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18C043AB131D6F9A202D782D5503B0002F37D1D7B541E6860B3A5ECEBB5A8D8E90B7F66 |
|
CONTENT
ssdeep
|
3072:eX8yLppsa/7nkA1j7XJPuTXE35/eUMXN4UGQmRl:S8yLppsY7kU7XJPMU35/eUMN4UGQ4l |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ddc3338d0e329999 |
|
VISUAL
aHash
|
e0f8f8d818180000 |
|
VISUAL
dHash
|
081030303232300c |
|
VISUAL
wHash
|
fef8f8f8f8989000 |
|
VISUAL
colorHash
|
380060000c0 |
|
VISUAL
cropResistant
|
081030303232300c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.