Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14FF322D19885303F908A7045A779F369B7D28141CF051E6447F9E7AECBA7F81ACB324A |
|
CONTENT
ssdeep
|
1536:AiTJklUk5ueOmf+0hy1MNzN3cSPEfj0REO4o5/Rn/n1HgHz91Ft/x:ATlIM5N3c90REO95/Rn/nIt/x |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed699a921ac3c3c9 |
|
VISUAL
aHash
|
ff83e3c1c3ffff97 |
|
VISUAL
dHash
|
2b27070727510e2c |
|
VISUAL
wHash
|
e981818181ffe797 |
|
VISUAL
colorHash
|
06000038000 |
|
VISUAL
cropResistant
|
2b27070727510e2c,2d4606d3c3c34327 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.