Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T140E293304146AD3701A3D2E0E6B1AB4B63D082C5CBB70755A3F8C39E9FCBE99CD56259 |
|
CONTENT
ssdeep
|
384:Wo1oXSwzvi5o5M575E8dVhhmgZz5Zh1rJjLfzQ+fBZDNKqvdWupGhuHZPt47:ZmXA0w1x8gDKqvdYhuZt47 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ececb113c7e44e12 |
|
VISUAL
aHash
|
fffff3f300000000 |
|
VISUAL
dHash
|
373737276969c4c5 |
|
VISUAL
wHash
|
fffff3f338080000 |
|
VISUAL
colorHash
|
0f0020c0000 |
|
VISUAL
cropResistant
|
3737333727272767,00002828b02c0200,0002686968680000,0000303830100000,0000616060600000,372727696974c447 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 727 techniques to evade detection by security scanners and make reverse engineering more difficult.