Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1965361713D027826219F45DFA227260EA2D0C7CAD62229D5B6F4D32D9FF2D41FAF2254 |
|
CONTENT
ssdeep
|
768:2gEGb6waDAuzULDAuzUWRTuDAuzULDAuzUg94jMsIaofUf7F8F:9EGbXRRTT9RseQ7F8F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9808e5fb139bc52b |
|
VISUAL
aHash
|
0000000000ffffff |
|
VISUAL
dHash
|
94b6f6bdbd1a19ba |
|
VISUAL
wHash
|
0000120c0fffffff |
|
VISUAL
colorHash
|
06c00000000 |
|
VISUAL
cropResistant
|
9c3238183819baba,9196b6b2f6bdbcbd |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 302 techniques to evade detection by security scanners and make reverse engineering more difficult.