Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13133D6DBE291BC2F6233A5D9760E5B0690AB928FC9372A04F16646F35FF1CB0D50507A |
|
CONTENT
ssdeep
|
768:Adgncxu0IVkGbrcfS4GSg0yRj0WgFgTzZ4p1ttEJUxycgx3hH/o:AOnHVXypF64ttEfU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b16444ce67e764a3 |
|
VISUAL
aHash
|
0000c3efefefefef |
|
VISUAL
dHash
|
e6b49e1a9a1b594a |
|
VISUAL
wHash
|
000002efefefef2c |
|
VISUAL
colorHash
|
00000000e00 |
|
VISUAL
cropResistant
|
80908c8c8c808080,80808c8c8c808080,8080848c8c848080,80808c8c8c808080,80808c8c8c808080,e6b49e1a9a1b594a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1254 techniques to evade detection by security scanners and make reverse engineering more difficult.