Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10A326233A500C92A4DAB56CCF2C49689521ED346FB314CC6B26091BF7BC9DF065A93AD |
|
CONTENT
ssdeep
|
192:fYcUcbchncNnoLy2899CSaCSO4NaGRxhMcnthWeNWbnfMmUU8VCobAn:gcUcbchncNnoLeCScOI+fMmUFCobK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed6d9a9292999866 |
|
VISUAL
aHash
|
f7e1c1c3e3ffffff |
|
VISUAL
dHash
|
2f2707074f100200 |
|
VISUAL
wHash
|
01010101e1fffdfc |
|
VISUAL
colorHash
|
07202008002 |
|
VISUAL
cropResistant
|
2f2707074f100200,f1f3c4a2ac29089c,0101010101014113,b93232a6ca93b45c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.