Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1864333722560243613BBA6E45E106B1D71C6E309DF0689C423F8C75EEFC6EDCD6A319A |
|
CONTENT
ssdeep
|
1536:x6QwdbT3oskPH4cYqB7IhIfFoxwIMIYBkIahRokRVNz:YwH4cYyFox5okRVNz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ba1cc4c9ba96b469 |
|
VISUAL
aHash
|
ff00008181ffffff |
|
VISUAL
dHash
|
00e03f3b332bcc4d |
|
VISUAL
wHash
|
ff000081818dffff |
|
VISUAL
colorHash
|
06001000180 |
|
VISUAL
cropResistant
|
0000202727200020,3f3b333b29cc4d4c,606106d3d03f3f2f,7a6e7cf8f199f8fc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 503 techniques to evade detection by security scanners and make reverse engineering more difficult.