Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12E221283110C1A15C3B3498594443684E187E68FC9A58AB0D6FC4D3B1BE6FA276E6F7F |
|
CONTENT
ssdeep
|
192:4PceO+3CzkHjbu1jZRAUGojw8A34yMiKLzjwSA3FPCponZO23aLX8Yk+hMdqw:873CzkURw8hO9SSQ44yaAYhEv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d211fa2d05fa2d47 |
|
VISUAL
aHash
|
0c1e3c1e3cfcfcfc |
|
VISUAL
dHash
|
dcdcdcfcd4410109 |
|
VISUAL
wHash
|
0c1c1c1c3cd4fcfc |
|
VISUAL
colorHash
|
07000000e00 |
|
VISUAL
cropResistant
|
dcdcdcfcd4410109,20a0447232320420,a508d3c7486016c6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5 techniques to evade detection by security scanners and make reverse engineering more difficult.