Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T163327033A600DC2A8D9B46C8F2C49589551DD385FB3188C7B2A491FF3BC4DF169A93AD |
|
CONTENT
ssdeep
|
192:Kh+DqVd/OCvdxVdxcmbkxwMcnthWeNWbkfMmUU8VCo3:XqL/OC1xTvfMmUFCo3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3338c4ec5c54e8e |
|
VISUAL
aHash
|
cfc7c7c3c380ffff |
|
VISUAL
dHash
|
191d199e1f250000 |
|
VISUAL
wHash
|
85858581c580ffff |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
191d199e1f250000,0080808088988800,41102cb2b20c1041,0000000142420102 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.