Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14F7313F0534014AE0AD2FAD496A27E0761B6C9E6E21F6ECE91A8590D1EC1FF5CCC07E5 |
|
CONTENT
ssdeep
|
1536:f8D6dTTTFW4lZ8Ry2DeJ3OV0+WOYsppsKPC7Rs8VjN4bsIe:f8DAT9fsg2XsN |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
edb612e949c992c3 |
|
VISUAL
aHash
|
ffe7ffd9f1f10000 |
|
VISUAL
dHash
|
2b0f2b33331393d4 |
|
VISUAL
wHash
|
ffc3ffd1f1c10000 |
|
VISUAL
colorHash
|
0ee00008000 |
|
VISUAL
cropResistant
|
2b0f2f3333132393,0004686961600620,a200e08e86968282,0000000000000000,59e4f1e0e08ce871,509c929284e4e01a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.