Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T150A3A431B069187A614782E8D2B8BB2A72F6E302CB4F8AD1C5F5C33E9FC1D95ED55148 |
|
CONTENT
ssdeep
|
3072:UwS8bkS59eJRn8JpJWJiTJZJOJUvaoba9+SedY:uxerQobYf9++ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cf4eb990991ee1c4 |
|
VISUAL
aHash
|
bf203000ffffffeb |
|
VISUAL
dHash
|
69656565d88e269b |
|
VISUAL
wHash
|
21001000ffffffe9 |
|
VISUAL
colorHash
|
06480000040 |
|
VISUAL
cropResistant
|
69656565d88e269b,ede5e4e4e5e5e4dc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.