Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E841D070D0158926EA4B09D5D5F8B7ADB4A7824ECACB2500FAEC46D447EAC41CA2AD90 |
|
CONTENT
ssdeep
|
24:hR/CPjlZcVDDl2yuI1djojhllYX+Pa3FxR8DerJGWD+Aq4+V6P6csG:T4zcVNVnZX+zAkW7q4+VEuG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8ca4b1b172cece66 |
|
VISUAL
aHash
|
071f1f1430383860 |
|
VISUAL
dHash
|
6ef6b2ece8f0f0c8 |
|
VISUAL
wHash
|
0f1f1f163c3c7870 |
|
VISUAL
colorHash
|
381c0000000 |
|
VISUAL
cropResistant
|
6ef6b2ece8f0f0c8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.