Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T171E2EC247484253B8AD763C872227B2F72DA81A2D2520E4471F59A6BCFF6F05DC152FB |
|
CONTENT
ssdeep
|
768:fF2+tQTKMofHGuRhADlGFSSBNSkc5SZc1SncESaccPbcNIWsK:i4gPBBt5Nz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b577a4846cca8b8b |
|
VISUAL
aHash
|
c702000000ffffff |
|
VISUAL
dHash
|
860c49282c103813 |
|
VISUAL
wHash
|
c7c2000000ffffff |
|
VISUAL
colorHash
|
07400040003 |
|
VISUAL
cropResistant
|
0020203b3b2400b1,6058505256561613,7970e982464e4ec6,f4b494b43471f8b4,1818161e02303317,868e4d496888246c,0000200010106080 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.