Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F064A6B1A3711DB95300D310EA381B5A5EF0C4B6E5016D17B6A6C7EBF80262E3FD589B |
|
CONTENT
ssdeep
|
1536:nSiVoDLLmeWTrc1sJKCjC9boCfCby6Krt3n/nWcr36SBxrhSQlSQgJLSTgTJPKdQ:WR4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b614eee809a389eb |
|
VISUAL
aHash
|
ff06060404ffffef |
|
VISUAL
dHash
|
2ccccccccc080c4d |
|
VISUAL
wHash
|
bf04060400ffff1f |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
2cccccccdc280c4c,2d2de2f392d7b2b2,6371636563636363,c424109010102020,871d7be7c1d76719,15d4d01b5216d630,7878787878787878 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2948 techniques to evade detection by security scanners and make reverse engineering more difficult.