Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BEC393D3423C047A17B78BEA154923293C9AE04FC9A916BBE37DC39412FAED139524D7 |
|
CONTENT
ssdeep
|
1536:qIcHiaZaM8SZn4/0Ibi7GEBtzmALAZAPAZsw5tChPtIbe+1z/pkY2wpp9JT8eMls:quz/pL2wpp9JT8ewZbpUpnjVbeqT5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed13924e16716557 |
|
VISUAL
aHash
|
00f3c3c3d3c1c3ff |
|
VISUAL
dHash
|
4d1317072303032b |
|
VISUAL
wHash
|
00e3c3c3c3c1c3ff |
|
VISUAL
colorHash
|
03000038000 |
|
VISUAL
cropResistant
|
031717232303032b,0000a2dccc442000,0f0b0b0b1b8b0b06 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 49 techniques to evade detection by security scanners and make reverse engineering more difficult.