Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C933A81062106D3F57AB42EDB7707BAA30E6A30AC25BD148F1FD03669BD1DC99D2347A |
|
CONTENT
ssdeep
|
768:uGSGgVYSJePrNfBmZG1H4c2bw/IdWEGL1OZCsCknAL1OGL1O4L1OwL1O3BQdBk+c:urZYiePrjmZgEVQu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f19c633c1e631e31 |
|
VISUAL
aHash
|
00ffffff9fff6060 |
|
VISUAL
dHash
|
249382323a2acac8 |
|
VISUAL
wHash
|
00fbf0ff8f9f4040 |
|
VISUAL
colorHash
|
06402008000 |
|
VISUAL
cropResistant
|
639302c2313a3939,27363a341c1e1d1d,249382323a2acac8,f8e0451717c5acab,cf4ed773b2d4544f,183fb1a445c1a909 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.