Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12481E030A85868370393A3D95FB5A75AE7D68185CA370B0721F1CB8E5ED3E06DC13E66 |
|
CONTENT
ssdeep
|
96:bsJFcotS1nADQBu1dNxnQFdGGya2BlWhSFVmR:IFc+SZBu1rxn0ByDJy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
db5364315b4b7131 |
|
VISUAL
aHash
|
00e0c0fcfce0fcfe |
|
VISUAL
dHash
|
9408806168881000 |
|
VISUAL
wHash
|
00c0e0fcf8f0fcfc |
|
VISUAL
colorHash
|
0000000001e |
|
VISUAL
cropResistant
|
a905360e26d46868,131395aaaaa99496,9408806168881000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.