Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T137D1A97190A2A53340B3D5E7D17A3B1961E3824DE9A22211A3FC83AD1FDAD5BFD03479 |
|
CONTENT
ssdeep
|
96:T/HVGpXXXXXXXXXXXXXXnBB0KSDHNDXXXXXXXXXXXXXXpILXXXXXXXXXXXXXXpDx:EreJDcBGzmP8de |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dd82a5a56d9a98b4 |
|
VISUAL
aHash
|
fffffff8c0808000 |
|
VISUAL
dHash
|
8200000000000000 |
|
VISUAL
wHash
|
fffffff0c0808000 |
|
VISUAL
colorHash
|
00003200080 |
|
VISUAL
cropResistant
|
8400000000100000,0000000000000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5 techniques to evade detection by security scanners and make reverse engineering more difficult.