Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T149F152B84515A92B639393E5BA762B2FB2C38344CB530F4162F9836E0FE8E95CC37401 |
|
CONTENT
ssdeep
|
96:TFVCJBByG2CsMyfSdL0CJBBy8QCsRyfSs:5VCJBxvdL0CJB/As |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e492996b9a4c8f93 |
|
VISUAL
aHash
|
ff7f32100001c0ff |
|
VISUAL
dHash
|
b2cee466eb0786aa |
|
VISUAL
wHash
|
ff7f36100081c0ff |
|
VISUAL
colorHash
|
06c00000000 |
|
VISUAL
cropResistant
|
b2cee466eb0786aa,0804383032700c20,cfe272b7e36b0393,3061870d364e4b5e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.