Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T112E2C611F3402A39139303EDF620637AE7439389A35236646AE75BFC79A5F65D83708B |
|
CONTENT
ssdeep
|
384:JMDDgRXDII2RD4yKa7V2nX0hPAAKlhSMcai/ADzbzGPE0l6fBZ/0PJmLt/p:JYkyZ7U5zhS9/AD/CE7fPaSz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b069cfcb649c3139 |
|
VISUAL
aHash
|
ffe7c3c3c3c3ffff |
|
VISUAL
dHash
|
330e9e9e9e9e9016 |
|
VISUAL
wHash
|
99c3c3c3c3c3c3c3 |
|
VISUAL
colorHash
|
07600010000 |
|
VISUAL
cropResistant
|
330e9e9e9e9e9016,f5d3c7e7eb9bdf6f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.