Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T118437480F191313B024B93D5A6A4AF26B3D68245CF421B1167F1E7DEAFE3D40DE5A12E |
|
CONTENT
ssdeep
|
384:s+myJuRSkG0W2HByeXDFLA5x4V3E9Hxoj4qyq9mUyL94jJ6qhlHdYU5vjUB9lPY3:s+OEkG8hy6VPfPyKdjjwYtk+rx9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed6d939252d290b5 |
|
VISUAL
aHash
|
ff00000000ffffff |
|
VISUAL
dHash
|
c0a3636363140e40 |
|
VISUAL
wHash
|
ff00000000ffffff |
|
VISUAL
colorHash
|
06007000080 |
|
VISUAL
cropResistant
|
80e023a36363a363,82b0a082aa90a492,610686160e080000,63a3a36383a36363 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.