Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T146523120328E609F130775EBF5056B0D79E785FEDF6B4B0935B429FE33E2854891921A |
|
CONTENT
ssdeep
|
384:tIxApIIdHZUgqYmBABuxH3Ynl1mnVOnXsUCnQaYc4/E+O15fI:tICpIIdHnXuRklgVu8UiQ015fI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0674f3c33184f4b |
|
VISUAL
aHash
|
00ffe7c7c7c7dfff |
|
VISUAL
dHash
|
078e0f9e9eb6b2aa |
|
VISUAL
wHash
|
00c3e7c3c3c3cbcb |
|
VISUAL
colorHash
|
07411010000 |
|
VISUAL
cropResistant
|
078e0f9e9eb6b2aa,40514573714d0140,d9d6d7d79cb4b2f1,176f6f664637e5c4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.