Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13413CC20A800ED3701DBA5D96672476A62F68341CA230689FBF4C3F95BEFC28DE77155 |
|
CONTENT
ssdeep
|
768:owsIx/jvw+rMfgneeeHeeeneeeEzEULjooKVyUf79F:JsIxTw+rMfgneeeHeeeneeeEzEU/ooKT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9262ed11d26d9f4a |
|
VISUAL
aHash
|
4246040c6e0e02ff |
|
VISUAL
dHash
|
849429cddddc16a9 |
|
VISUAL
wHash
|
4246046e6e0f0fff |
|
VISUAL
colorHash
|
30200030040 |
|
VISUAL
cropResistant
|
796969e868b2e871,cecece4763cecece,9e070f0e0a0e0f84,9c164f1f0f0f0ecc,02002a2a222a0000,849429cdcddc16ed |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 73 techniques to evade detection by security scanners and make reverse engineering more difficult.