Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19533753220005D3B1A63CAD1CB32370E53D9E356D9361A05EFF897B91EEADA4DD27684 |
|
CONTENT
ssdeep
|
384:l/gkx6IUq8B1aunYdO/OjYVnUVsgXcCg4kkCgVCOqJH3ixk:JqB1aunYdO/OjYVCeEkkp0Kk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e5609b7db0c256a5 |
|
VISUAL
aHash
|
00002060c280ffff |
|
VISUAL
dHash
|
8486c6c686068048 |
|
VISUAL
wHash
|
000070f0e3f0ffff |
|
VISUAL
colorHash
|
0200024000b |
|
VISUAL
cropResistant
|
88cc9e9f9e3e3c5c,999ba42666a5bab2,4c67253078f2a7e6,c149647626aaa980,c786066200000c14,848287c6c5860600 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.