Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E7B153B28158657B0142D3C0427BB2B7E283D40FDF070A15E7E45799CA9DEE2ED7216C |
|
CONTENT
ssdeep
|
96:DIqN2X0EWk1GiUt9i2WITSZSZSZSXWdTSZSZSZS2nf0HujLaVXH:EqgX0Osy3IeIIImdeIII2f0f |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e1c1703e1f371e52 |
|
VISUAL
aHash
|
427b7e7b9b818100 |
|
VISUAL
dHash
|
b6928a96333303aa |
|
VISUAL
wHash
|
427b7a7bdbb98100 |
|
VISUAL
colorHash
|
09600018000 |
|
VISUAL
cropResistant
|
60c0c0c0a6385e8e,d3d2e4d4d8f4f6cf,e8d6b60736b29632,f3f1e1f0f0f1f0e1,606060f0f0f1d068,b6928a96333303aa |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.