Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B2C35432D1912937508793C4B6746B3FA296C24ACE0B0B154EB5E32D2BF3DA1DE5A31D |
|
CONTENT
ssdeep
|
1536:+u3zwg2YfUOAyOa1leB0HrFPL8TwroIcIYIQIKIOmxtN:+uDX2qnv+rTL2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
abb0944f4c6394fc |
|
VISUAL
aHash
|
ffcfc7c18161e1ff |
|
VISUAL
dHash
|
35ab890b23c3cb24 |
|
VISUAL
wHash
|
ffc7c701012141ff |
|
VISUAL
colorHash
|
06400000006 |
|
VISUAL
cropResistant
|
35ab890b23c3cb24,dcd8d8999c048c8b,252505253b94c423,4a6c9c0e87c1c7c7,80904d333309a200,01929a0cc42120c0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.