Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CA72D99381954E22028340B2FB34AB8DE3508254D3A72A5111FC86AE7BC9CF4EFF75D9 |
|
CONTENT
ssdeep
|
384:0XvQYxr46xC9GVjQoS797quJae/UiG6rL7:4QYl1x2GLS7xquJae/dJr3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c66d4d65664c5d46 |
|
VISUAL
aHash
|
00ffffffe7ff7e3c |
|
VISUAL
dHash
|
060c4c4c4d696169 |
|
VISUAL
wHash
|
00ffff24243c3c3c |
|
VISUAL
colorHash
|
07000038000 |
|
VISUAL
cropResistant
|
8e4c4c4c4d706969,10a440656445a419 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.