Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15534DDE44069442E0CA283DAA27D5B1F63D5E227D693B215E7E887A7479FCD8EC37430 |
|
CONTENT
ssdeep
|
3072:W053CYSNPirydMoO1CsITW3qqrneiMo5KWSnydKLjnNEKuKvK2O4qUCg3yMUacMs:ETkhEKMtcoWtMKBZ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92ea9e69846b2e2d |
|
VISUAL
aHash
|
ffffe7460000003e |
|
VISUAL
dHash
|
b1fd8d84943644e4 |
|
VISUAL
wHash
|
ffffef660000003e |
|
VISUAL
colorHash
|
17402008000 |
|
VISUAL
cropResistant
|
ffffffffffffcfcf,d84bcbdbdadbb3a3,33a9cccc8c8f9796,b1fd8d84943644e4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 40147 techniques to evade detection by security scanners and make reverse engineering more difficult.