Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10952BDB51001ED3756E3C2E59635632FA2D2978DED83575693FC8B0E8BDEDA1EC21022 |
|
CONTENT
ssdeep
|
384:8+OYV44NjSIIII42o2ohJ3dFDc1y4Q/ROZVf:YYV44NGIIII42o2ohJ3dwy4Q2R |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec65989398c76d98 |
|
VISUAL
aHash
|
ffc3d1f3ffffdf8f |
|
VISUAL
dHash
|
2b162727384eb436 |
|
VISUAL
wHash
|
d98181c1dfc38f8b |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
2b162727384eb436,37cbcb35d491b233,45818199a5a51985 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.