Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14114F73C210029BF902386E9F4647F49E175F31EDB669C48EBF992657FD6CA0E894234 |
|
CONTENT
ssdeep
|
1536:aduzmRmHnUM7vaGUM7vaGUM7vaGUM7va2pUj7SIqSAvnMoFkGRpoVCt7RI1/7S2y:adOH00ooFkGQIIDssq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b032eb6b499716f0 |
|
VISUAL
aHash
|
01406606c000ffff |
|
VISUAL
dHash
|
3b878cdca90ca2b2 |
|
VISUAL
wHash
|
8141662ee400ffff |
|
VISUAL
colorHash
|
38000000e00 |
|
VISUAL
cropResistant
|
acd2b3b139bbc658,3b878cdca90ca2b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.