Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T112518460821258356E6391C17ADD1B0B3AE8CD89B47715488FECD27C0FEED04EC2E4D4 |
|
CONTENT
ssdeep
|
48:T1l5DevwlQKp/TOAeoVt8tUW0gTe8asYbVluJeTS:T1XDevOQK8voV2tv0whas0VZTS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e2e16d3838cdc6c6 |
|
VISUAL
aHash
|
e0e0f4e446060103 |
|
VISUAL
dHash
|
0183c4cc8ccc873e |
|
VISUAL
wHash
|
f0e0f4f6e7470303 |
|
VISUAL
colorHash
|
38000038000 |
|
VISUAL
cropResistant
|
001001f236310000,0183c4cc8ccc873e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1 techniques to evade detection by security scanners and make reverse engineering more difficult.