Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T164024432C0C6656F134BC1C2E177F9D59842F60EDAAE4E55E6D90B89F381EA4F871184 |
|
CONTENT
ssdeep
|
192:UprG4wAnYN5og70pMqRa9kIp2D2s2D2D2D2E2D2w32D2E2D2q2D2U2D2E2D2g2DT:wwAYN5og70pzRKp2D2s2D2D2D2E2D2wz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
855e6aa17f8c3869 |
|
VISUAL
aHash
|
0000183e6e7f7f00 |
|
VISUAL
dHash
|
717170e4ced6d2d3 |
|
VISUAL
wHash
|
0018183e7f7f7f28 |
|
VISUAL
colorHash
|
30400038000 |
|
VISUAL
cropResistant
|
fdbd2e7cf1c2c28d,3b1b96a4a8b1f372,dec7c6c6cc989c9c,d0cfcece8cd81c9c,c6cece8e8cf42c1c,a82ad29d95157567,717170e4ced6d2d3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.