Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T159B1A7331540956F1187E5D2FE6623AA92E1C228C61B6E18E1FC93DD2BCECA6CC79610 |
|
CONTENT
ssdeep
|
96:T+qlLFcBRCRMM7pRMj4/ZNAR9GMaHYAhTVNqOAi:iqP9R/Ri0jMaHYM1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fe5bb04bb41145b4 |
|
VISUAL
aHash
|
818180003018fff7 |
|
VISUAL
dHash
|
313129656161242e |
|
VISUAL
wHash
|
81d99080b838fff7 |
|
VISUAL
colorHash
|
06003208000 |
|
VISUAL
cropResistant
|
c5cac284890a0549,b8dcdcdedfcfc7eb,61616171602e2e2e,3331316965616161,79f9f2c54d4c6872,c7c3c2c04f4f6367 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.