Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A78266B2534427BE4FC6E620757AB594E319C5F1F21208D9427D8D5C26C0BB8CDBEBA8 |
|
CONTENT
ssdeep
|
384:u/E+EL0Ig7yaJmRp7SlnN0B8B2JxzVGkVq:u/E+xsakrbev |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b39930cccc6c9976 |
|
VISUAL
aHash
|
ffc7c7e7efcfc7c7 |
|
VISUAL
dHash
|
309d1c0c48180c0c |
|
VISUAL
wHash
|
dcc4c4c4e4c4c4c4 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
309d1c0c48180c0c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.