Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11DC1A43162151E3D521387E0F654B72D61AF838ADA1F8A1CF2BD43E657EAD84EC23384 |
|
CONTENT
ssdeep
|
96:1pUyAk5ds9HEM7xFgZkNNbINYd7iDQZhGk+e+Gk0rlFgJr4koq0Kr4kGqJ:4+zsp5ssNbLdu0yPOAr4Ar4uJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8cf6f3712323558c |
|
VISUAL
aHash
|
c3df991818181818 |
|
VISUAL
dHash
|
0f333363323171f1 |
|
VISUAL
wHash
|
c3ffbf181818183d |
|
VISUAL
colorHash
|
380010001c0 |
|
VISUAL
cropResistant
|
0f333363323171f1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.