Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E59382218950263B109B82D0A5F4DBEAB3D38257DB2317068FF4D75B1FEBE80DC25A59 |
|
CONTENT
ssdeep
|
768:X1rJMoiiEJMokMiBX3rs6oQE27rpu7fISnxMiW7OUeTpqDeVZHL8nD+1qn+mM7lU:5Mx7fBx+7OiD+1U+T7u |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f25a252d254e7c0f |
|
VISUAL
aHash
|
00fcfcfcffd3ffc3 |
|
VISUAL
dHash
|
aeb9190d0eb60896 |
|
VISUAL
wHash
|
000cece4efc3e7c3 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
aeb9090d2eb60896,0012523034343212,8060909090a00000,138ccc13a4a41b84 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.