Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E3F3E9B0F560447E426F91E6F3727B1DB2DBE306EA8D07D9D1EA4BA845C2D60EC5304A |
|
CONTENT
ssdeep
|
1536:NBTGU1XvHw2wHPsbWuKkJdsOdGr30ehzv:NoK8uKEbGr30eV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b81f4d4349483ecf |
|
VISUAL
aHash
|
000287c7c7c7ffff |
|
VISUAL
dHash
|
f23e2e1b8f2f1b63 |
|
VISUAL
wHash
|
000087c3c7c7cfff |
|
VISUAL
colorHash
|
0f000006200 |
|
VISUAL
cropResistant
|
8080828282828080,3e2e2b9b2f1f1373,f2f0f1392cc4d58e,e2e2620d68611e5e,b23a39333339342e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 26 techniques to evade detection by security scanners and make reverse engineering more difficult.