Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1723352B0B1527A7F11D3C3E277716B5BE2E2C344CA671A5A93FA83881FD2C51EC62254 |
|
CONTENT
ssdeep
|
768:n0a+Y3sisLzAF/IyI3/nAsmeQe0WXy7NZNnHlpVp8n0HByBLN:qY3sisLzw/Iyk/nAXo3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3c7983c39669cc6 |
|
VISUAL
aHash
|
007c7c702000307c |
|
VISUAL
dHash
|
9cd4e0c0cde0e1f1 |
|
VISUAL
wHash
|
4c7e7e786018787c |
|
VISUAL
colorHash
|
30600010000 |
|
VISUAL
cropResistant
|
5252ada5e4ec497d,129a17b7b46435b4,b696b6594db69696,9cd4e0c0cde0e1f1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.