Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19A83353C6280993944CF86E2E5B59E35D1BDCB99DB136DCAF26CC386178EC59CB63110 |
|
CONTENT
ssdeep
|
768:kUf7vsIx/jpaiFfFqdiAbfXHwo4xBg28JVV61v3PZ4GEWbdhVzeliu/3ycyQTso:r7vsIxdfod+x1v3PREWbq/3Pl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
82add5cbc3d28d94 |
|
VISUAL
aHash
|
ff03030507030400 |
|
VISUAL
dHash
|
ebaff7edefe7fdfc |
|
VISUAL
wHash
|
ff07073f1f1b0c04 |
|
VISUAL
colorHash
|
0b406000000 |
|
VISUAL
cropResistant
|
c0d0d1646b2b6bcb,f8ffff979fcdffff,efb7edcdf7e1fdfc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 32 techniques to evade detection by security scanners and make reverse engineering more difficult.