Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T183C20270569A647F0143E0DBE920AF0E3AE281FDFF67570516F41E6E2AF3C54CA2A215 |
|
CONTENT
ssdeep
|
384:wE062dMW9LAlDixJ9z6hCOL3qyxy0a+fL3eOGsmOFnBWM:u6iM8AtVhvqlgLKCMM |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e74398b8b8e48cbc |
|
VISUAL
aHash
|
ff000020ffffffff |
|
VISUAL
dHash
|
93d9e0c626c6262e |
|
VISUAL
wHash
|
00000000f7ffffff |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
0002603737300000,f2e09c9e2c5c6464,cdcd5a6a1ada0c2c,c026262704262e34,46d9c9686969c0c4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.