Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19983527581004079222353DD777A6F9BD1B38BF8AEE2D5F9C9F8839A3653D11643822E |
|
CONTENT
ssdeep
|
768:Ea09A6z3MswhbtWtwtgtgtgtGtutAts0J555v/9wZldGeEwEgEgEgEGEuEAEjPiJ:S7USZldUffhof83A |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c643b93cb9394c93 |
|
VISUAL
aHash
|
0070707074307fff |
|
VISUAL
dHash
|
d2c4c0e0e4e4e030 |
|
VISUAL
wHash
|
007070707470ffff |
|
VISUAL
colorHash
|
03000000007 |
|
VISUAL
cropResistant
|
a326a124268666e6,730fcc159574870b,4b7766e67ebeba9e,2300200038300222,10c4c4e2e4e4e4e4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1 techniques to evade detection by security scanners and make reverse engineering more difficult.