Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14803B6717151763B11D3C3E6B771275FF2E2C244C6A71A56A2F6C39C0FE2C22D8622A6 |
|
CONTENT
ssdeep
|
768:s0a2CZl6YJl2JEyJZBXwCqNIacfB7TzYnfHlpVp8n0hByBLN:XCZl3l2JEyJZBXwd+5t |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
edce6d839292929c |
|
VISUAL
aHash
|
fbc1d3dfffdfcbc3 |
|
VISUAL
dHash
|
673737383c929296 |
|
VISUAL
wHash
|
b181818fdfc3c3c3 |
|
VISUAL
colorHash
|
06400018001 |
|
VISUAL
cropResistant
|
673737383c929296,f696f6595da696f6,6573983cb99a69cd,60e0f8f860799cfc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.