Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FB8364347801686630EF46CFE273798E2284EBCAD95619D9C6F0472469F7CA1FED12D8 |
|
CONTENT
ssdeep
|
384:/Wac2KzXQr0bV/GT5BZB7E75CzzeP4a7a3pGHa7a3pGda7a3pGga7a3pGka1ca7s:/3zzew+C |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bf441f661d4c37c0 |
|
VISUAL
aHash
|
00ffffdbe7a5c18f |
|
VISUAL
dHash
|
404d16334d0d2b19 |
|
VISUAL
wHash
|
00e0ffdbe781818f |
|
VISUAL
colorHash
|
06000038000 |
|
VISUAL
cropResistant
|
404c32334d0f2b19,000000000050c040,990f0f66274f0f1f,c0c3e73c38988ccc,c0f0e50a170c3cf2,1c96be2e64f0f8f8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 631 techniques to evade detection by security scanners and make reverse engineering more difficult.