Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14851533020154C7BD08386E85BE4D60A61C9C261C7635B8593FCD7BD5ED6E42C9A63A0 |
|
CONTENT
ssdeep
|
24:hEXBuNYfMvD50uDfr3dSa/ZVSspkJifpf3nKhZZnnSS1UHFDKAWHNn9uzQevglY0:SBu6WWCDFWSgiftY5nS+Ulo33wfGvS+h |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cd9df6b4498c3622 |
|
VISUAL
aHash
|
fe7f3b78d883f0c0 |
|
VISUAL
dHash
|
34e847f3930f8080 |
|
VISUAL
wHash
|
fe7f3b38d883c040 |
|
VISUAL
colorHash
|
07c00000000 |
|
VISUAL
cropResistant
|
287880a0a0a0a03c,3c3c009080800018,34e847f3930f8080 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.