Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T135917570F004BE3B51ABD1C4ABB5E74B72C1468DDA8367020BF993E88ADBCD9ED06145 |
|
CONTENT
ssdeep
|
96:TDIFpAUyWbvbK+Af430TJnK+SbE/XjNRSr8I7FkJnLoCR:IFpByMuf430Tn/jbe8I5kJnLo0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b333594c66664c5d |
|
VISUAL
aHash
|
00ffe7e7e7ffffff |
|
VISUAL
dHash
|
4c1a4c4d4c280c00 |
|
VISUAL
wHash
|
00002424243c3c3c |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
dc124d4d4c2a0c00,0000804040008000,0471306c69610401 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.