Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A79250315C467D3B97A353D1D782936BB3D48284D5078E66CAFC8B5A1FD3E81EE22209 |
|
CONTENT
ssdeep
|
192:CmFMTmLz91igMfHPo1C2wQEsAnBLTtVXE1wOhVf2L+uv9e7JjFYQ:rFMTmLz9TeHA1C2w/Fqy0+6uv9e7hFYQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d3544c716c7279cc |
|
VISUAL
aHash
|
00ffffe7ffe7ff00 |
|
VISUAL
dHash
|
8ce8490a3a4acc32 |
|
VISUAL
wHash
|
007f2c24fcc0ff00 |
|
VISUAL
colorHash
|
00030000000 |
|
VISUAL
cropResistant
|
e8e04b68324bccf4,7a6afcdcd4d2dada,8689e8de8ea69140,53989c9656cc6c28,e10f5e4aca0f0f0f,4c32b24c30b2300c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 16 techniques to evade detection by security scanners and make reverse engineering more difficult.