Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T185F3C8B67344667F00A386FB72CE7B3592A8D349D9B3C5C9A5DC89F46349C10EF22648 |
|
CONTENT
ssdeep
|
1536:0mPYxmq9tgLiZOr7ShMeYui2OVxSnG9pufM/a3ZDqS8ZY7rglB:0PtgL6Or+OoOS8ZYHIB |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e55c1ab567126d38 |
|
VISUAL
aHash
|
00d8f0f0e3f36e04 |
|
VISUAL
dHash
|
d43012c6c6c6898d |
|
VISUAL
wHash
|
00f8f0f2e3f34f60 |
|
VISUAL
colorHash
|
010060000c0 |
|
VISUAL
cropResistant
|
5a5a52c4676e8dcc,1c52968e66a1b0a4,e48484191d8484e5,80200c1e16200080,d43012c6c6c6898d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.