Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BA731122281E456FB247D3E192F4FAA7DD91C905CE304F40DAE5EFCACA91F12B675128 |
|
CONTENT
ssdeep
|
768:Yhn0o7fnS4VeTRBLjthLtDNFAgI8iMaI6Wp6KgPEU0yesX7:G0Cq4VpX7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f0e50f42129739dd |
|
VISUAL
aHash
|
00f3dbfffc000000 |
|
VISUAL
dHash
|
c5a6b2b29099581b |
|
VISUAL
wHash
|
00f3fbfffa403c00 |
|
VISUAL
colorHash
|
30400030000 |
|
VISUAL
cropResistant
|
f6e060e1d8f2dcd5,86c5c9a8a49399a9,f0e0e0e090903839,9090ad65542a590a,a2f2a70fab2772f0,c5a6b2b29099581b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.