Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A783C870D1502B3A095783D373A0FF6CA3D9C282D6174999B2F993E693D2CD4CF89968 |
|
CONTENT
ssdeep
|
768:VKFbebQ9jgC7ocuQjTsdhSpSY+f4rIiVT43Qv4uFbaDYjxb4DYw7q:VYbebWGSba0Vb40wO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9145baeec239c53c |
|
VISUAL
aHash
|
ff00000016ffcfdf |
|
VISUAL
dHash
|
0ad4d4d4b400393a |
|
VISUAL
wHash
|
ff00000006ffcfff |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
001b1b006b2b2082,d4d4d43402183a3a,8a880a4e4e08ca8a,aab2cc4d4dc8a2a2,d4d4d414d4d0d494,33460d0d677138b9,7f7f7f7d63438787 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.