Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BA732232D353190291BBD5CDF062479E2292878DC7134B75A3BC53BA7ECEDB67602298 |
|
CONTENT
ssdeep
|
1536:P7/zdWVXPGeepuqZLW5H57r64pTOVgeCAAeeadGbscnHzuecqAqAoAdAeeTY8eel:st57r64pmws0TyYGq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c66c2c329399cb67 |
|
VISUAL
aHash
|
0000387e66667e7e |
|
VISUAL
dHash
|
26a666584d4d5d4d |
|
VISUAL
wHash
|
0000f3ff243cff3c |
|
VISUAL
colorHash
|
06000038000 |
|
VISUAL
cropResistant
|
26a662584d4d5d4d,0606076914166565,5b5c39fc09091396,520096f2b6f6f252 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.