Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12E51212BE1389A96471550F1AD6030EC856E152AD742EE998AD0C22F0FFCFD305B322B |
|
CONTENT
ssdeep
|
48:hLhnFQ07f4ouQ07f4ouN07f4ou4TZTPLzoyc+u/SiKlNiQtiIii1iK+:hHf7wrf7wra7wrUTPHoyc/KiKlNiQtih |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
eb6f94900f92919b |
|
VISUAL
aHash
|
71f181b1b9fbffff |
|
VISUAL
dHash
|
83232b6363036002 |
|
VISUAL
wHash
|
01e18181b1c1ffff |
|
VISUAL
colorHash
|
060000081c0 |
|
VISUAL
cropResistant
|
83232b6363036002,6c92d2d2c2426262 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.