Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17113C6257350293A02A322EEB1C17B6AB1A5D3048732E4E55CAF8DF577C2E7A343654F |
|
CONTENT
ssdeep
|
768:/ZIj0ZYJ8bcf7n2h8fIzAezOXpUurKpP1PWh:/2gY6c7nIzaXpUVpP1uh |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
db2c32c33493c73c |
|
VISUAL
aHash
|
00181818183c3c3c |
|
VISUAL
dHash
|
4c32327050585859 |
|
VISUAL
wHash
|
2e18183c3c7e7e3c |
|
VISUAL
colorHash
|
30200030001 |
|
VISUAL
cropResistant
|
d9c8b4f0b0f0d8dc,118884968e8392dc,4c32327050585859 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1 techniques to evade detection by security scanners and make reverse engineering more difficult.