Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17D1419A67144623A8213B0B9BAAB534DF7B5C16483161049D19E839C29F1C78C9FFFF6 |
|
CONTENT
ssdeep
|
3072:Glb5KNefIFwyiYAAco+L6Jf8gtOiH6XaUxJf6P70T5duAXppAPBlfm/vdHt6kdSh:GliefIFwybqo+L6oiHEaUxQP70T5duAK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
877898a77878a5d2 |
|
VISUAL
aHash
|
00000000333b3e7e |
|
VISUAL
dHash
|
8f004a004a46ecfc |
|
VISUAL
wHash
|
cf0000003f7f7f7e |
|
VISUAL
colorHash
|
30000008180 |
|
VISUAL
cropResistant
|
b293335333e3e3f3,a8ea8109a104a3a0,fffeb49c1ed8ffff,8f004a004a46ecfc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 618 techniques to evade detection by security scanners and make reverse engineering more difficult.