Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FA44D87462285BBD01A7D3D1AE34599E6758F20CF9C28CC461E8CF58DED2CE4DC478AA |
|
CONTENT
ssdeep
|
6144:1vnSvVMEgZSvVwMT1Agbnf+vPdZb5wnmvB7RfvB6n6N:jMnf+vPdZb5wnmvB7RfvB6n6N |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8c6c738cc31c6ce |
|
VISUAL
aHash
|
ffffffcfcfcfcbfb |
|
VISUAL
dHash
|
252b331bb31f1b33 |
|
VISUAL
wHash
|
90009bcbcbcbcbcb |
|
VISUAL
colorHash
|
06000038000 |
|
VISUAL
cropResistant
|
252b331bb31f1b33,d9cdbf9f9cdcccd4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.