Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EDE2623060516A3B41C3C2E6A3356B1FA3C2C246CA634B0567F4C7AEDFDBD91DD29265 |
|
CONTENT
ssdeep
|
384:yjIpsqg7BRUgWuuqlXR6Pgt79JL6BUOx/MsAX+rH95Lao:yjI+7fJWuuahMgt79JL6BUs/MJILao |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9417fb688c0972d7 |
|
VISUAL
aHash
|
0000061a1a40ffff |
|
VISUAL
dHash
|
b1ccccf67697992c |
|
VISUAL
wHash
|
00000e1b3ec3ffff |
|
VISUAL
colorHash
|
0f007000000 |
|
VISUAL
cropResistant
|
707ce8e9cccecec8,2eaa8ca68a9a9e4c,f056979799d0202f,b5ccccdcf676979b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5 techniques to evade detection by security scanners and make reverse engineering more difficult.