Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A3E2B671E6506A3F082383C8B751937AA3DEA386D1950245D3FCC7DA8BA7DD1F903589 |
|
CONTENT
ssdeep
|
384:FoRwW/ogwEPESTWjIIkpQvReZWFaPcGivG2U4osJM4f77Jl4ocNm4MPEEhJ6R:Fo05IeIIkGvRsH2j77Jl4or4wPhJ6R |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c36c97389364c73c |
|
VISUAL
aHash
|
000070742460643e |
|
VISUAL
dHash
|
ccc3c8c8c8c8cc48 |
|
VISUAL
wHash
|
7620707c6c6c6c7e |
|
VISUAL
colorHash
|
3820000b200 |
|
VISUAL
cropResistant
|
686ca6f3f3eea1e4,a7bdf44a0c2c2ca1,ccc3c8c8c8c8cc48 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.