Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EF23D93108C46F6F559383CCE321AA4FE395814CF676C69AF5DAC32A56C4D94C83AF98 |
|
CONTENT
ssdeep
|
768:p9wKyX2TbAHXQFOOAQx+9wE02RO/+dk2bSu1cS+DLYe/C3zEJbD:p9dyX2TbAHXQ8OAQxpWRO/+q0NGXC3zc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9416ebcac9eaca94 |
|
VISUAL
aHash
|
fd0606060606fffb |
|
VISUAL
dHash
|
71ececececec3b33 |
|
VISUAL
wHash
|
fd0606060606fffb |
|
VISUAL
colorHash
|
0e0000001c0 |
|
VISUAL
cropResistant
|
0021c96171c90152,96d6e8b094710f8e,803a380b73331313,ececececccececec,5a0fe6ceeec647c7 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.