Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T173E2B4329104753702D342E43F61BB4AB3A6900ADB175248A5FAC38DAFD7DB4DD3299E |
|
CONTENT
ssdeep
|
384:owrxwRhBZpxD6ciN0cRCj0DGRp0mL7TMpOlTsLnMPCpAKhwrUkrXxzuhmwdR:1wRhBlB07NOIAMkNuhmCR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92926d6d6f3c94c4 |
|
VISUAL
aHash
|
72666e0e3c200060 |
|
VISUAL
dHash
|
c4ccdc9cc0c8a4c0 |
|
VISUAL
wHash
|
7e6e7e0e7c20107c |
|
VISUAL
colorHash
|
30007000040 |
|
VISUAL
cropResistant
|
b4e6a7c82c717272,c4ccdc9cc0c8a4c0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1 techniques to evade detection by security scanners and make reverse engineering more difficult.