Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B2123331D4C15A3F029352C15F97B72AA28145C3E52BCA1A82FA469E9FCEF91DC37B14 |
|
CONTENT
ssdeep
|
96:33aTzVanN2aTzVaWpEPfAaTzVrw/MSJSJS19UqnDfKtKxwECPKnbtz1Is9URT3Yg:aTzVUTzVOpTzV4441S2Rz1GlYWYm5tTL |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92e66d31936696c6 |
|
VISUAL
aHash
|
0620746c6e0c0018 |
|
VISUAL
dHash
|
dce2edc9d8a93232 |
|
VISUAL
wHash
|
6670747e6e0e1818 |
|
VISUAL
colorHash
|
00000000038 |
|
VISUAL
cropResistant
|
66661e9c98f8f276,b4a8888c4b8cf0f0,dce2edc9d8a93232 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.