Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T145E33AA87370A37DB00757E8A2B1B46DB147A689F712C49893ED09417BC7C9E4D6C8D3 |
|
CONTENT
ssdeep
|
1536:1VlG1rpTgQZCWlXxJzIoqt6erpTgWyV/Y6SJKKRiKE2atw96j2atw96j2atw96jl:VAMWlXfUhcD0MY2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c09b3fe46c65613c |
|
VISUAL
aHash
|
007c4c7078604000 |
|
VISUAL
dHash
|
4ab9999091c9c9a9 |
|
VISUAL
wHash
|
877c7cf8fc7c6000 |
|
VISUAL
colorHash
|
30000600008 |
|
VISUAL
cropResistant
|
ec9db9a63e75ccad,f9ccccce72363c01,b8f0e0c6c78787c7,4ab9999091c9c9a9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1 techniques to evade detection by security scanners and make reverse engineering more difficult.