Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10A52BB31A294241FA39393C4FF31AB7A724381D3C7064B4666F05B2EEACAE558C355ED |
|
CONTENT
ssdeep
|
192:T+fQpqXamhsGSBuqy9rmzyATYXxfAWj43uuF7y9UFG//ALeLuuYp3Fbn1CMZkTgw:T+fQpksGSkFfy7Wmtr3eM8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3040409a5b3f7df |
|
VISUAL
aHash
|
0000ffefffffffff |
|
VISUAL
dHash
|
cc2b080c18584848 |
|
VISUAL
wHash
|
0000e7c7270f2f27 |
|
VISUAL
colorHash
|
07000000007 |
|
VISUAL
cropResistant
|
0084c0cccce08003,28480c081858484c,000002030b020000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.