Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A4A1E772000D28379313A7E0F6CA6659F2AD4116C709D84CAB7207BA7AFBC6C7E66914 |
|
CONTENT
ssdeep
|
96:JC6B0iNVn/FAkkpjZ7xK+LeHiayMWZuZPZK:xB0iNVn/F9k9Z7xSiagwhK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e667e1989a4aa699 |
|
VISUAL
aHash
|
e3e3e3e3ffcdebff |
|
VISUAL
dHash
|
4e464e4531111365 |
|
VISUAL
wHash
|
e3e3e3a11c0481ff |
|
VISUAL
colorHash
|
06606000000 |
|
VISUAL
cropResistant
|
4e464e4531111365,8200828282820082,8000818080808080,040bd0c4d0cc8c83 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.