Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T105342271DA4DAC7EA12353C3DB6477AA3192A256DD090508E6F81337825EE4BFC3B06D |
|
CONTENT
ssdeep
|
1536:xHr27vV6K4nFeNoRVVGpJW4Jo+YdHgJX9Y/SYn32lw:xHr27vV6K4nFeNoRVsJFJxYiJtYKY37 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c73be13c383c9236 |
|
VISUAL
aHash
|
00606e20187e3e7e |
|
VISUAL
dHash
|
94c8ccc1f4f4f4d4 |
|
VISUAL
wHash
|
00787e301c7e3e7e |
|
VISUAL
colorHash
|
30002000040 |
|
VISUAL
cropResistant
|
945555ddb6ed0d52,b498d97974ed0cb4,ecef8e9494a8cce0,a9333202696978d0,944a8c8c8cd6940e,729291995c6cec30,94c8ccc1f4f4f4d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1 techniques to evade detection by security scanners and make reverse engineering more difficult.