Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B7B395395358193DA9078BD0E6A5373C917ED2C9D72B885CF2BC01B25B82C4DE97B2E4 |
|
CONTENT
ssdeep
|
768:fb+Z6dklL5yEFyz+LCwhxjVtBWme92Y5555A5555V555581ImDSGA+PP2seennN/:fyp2kkefM |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8bdab8e8c8c2cbb8 |
|
VISUAL
aHash
|
ff00313201210101 |
|
VISUAL
dHash
|
2b7953c6cbc3c7d7 |
|
VISUAL
wHash
|
ff1f3f3303710301 |
|
VISUAL
colorHash
|
11003080000 |
|
VISUAL
cropResistant
|
0b4b1b2b2b5b03eb,2b7943c6cbc3c7d7 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 194 techniques to evade detection by security scanners and make reverse engineering more difficult.