Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EAB254B05644BA7B1663C5E0977A27BB3296829CCE53028653FCC3E81FEAC45FE27104 |
|
CONTENT
ssdeep
|
384:Whh8f442Ws/sp2Dpt4A1py2dpZEKisBoUQl4WeXzlOxBFybC1K7uevxGWB0F8:Wn0442WA/Ft4A1pyMp+e1eGLb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e2c9c96a69c86a6b |
|
VISUAL
aHash
|
f1ffe7e7e7e7f708 |
|
VISUAL
dHash
|
13484d4c4d4d8c32 |
|
VISUAL
wHash
|
f13ee467e6257c00 |
|
VISUAL
colorHash
|
07000038000 |
|
VISUAL
cropResistant
|
13484d4c4d4dcc10,0101d0b2b4010001 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.