Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F613DC2255C412B751F758CC7EF1F6E622E1E304CD8311C8E2AF57AC1BEBD5298634AA |
|
CONTENT
ssdeep
|
384:/PtmRdrWtiMmIMtoBw10YujCNwN9NnNGN4N3NuNPNfNOXgv4w60W400EYn+Z+qo1:6drjCYuj/Xv14 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c09e6f226e6e2ac |
|
VISUAL
aHash
|
ff18181800ffffff |
|
VISUAL
dHash
|
33b2b2b2b20c2727 |
|
VISUAL
wHash
|
1b18180000ffffff |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
0040603333680070,8ab2f0e0e033338a,4830372327372727,f2b2b2b2b2b2b232 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.