Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BBA21923A384233D02D3035677527B8AB77680E09B115D95844FC32DBA8A5AED6773F6 |
|
CONTENT
ssdeep
|
384:2Wmk8XTNT4xBBXyw8UvdVMjMoO8wdADBOYbh/NYrNHwlORo:2WVQOAw8UlVMj88LDBOYF/NYrNHwQo |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c793a4783c6d954c |
|
VISUAL
aHash
|
027c7e3e0026303e |
|
VISUAL
dHash
|
8ec8e8e894d4c0c4 |
|
VISUAL
wHash
|
027e7e7e0076703e |
|
VISUAL
colorHash
|
38003008080 |
|
VISUAL
cropResistant
|
69b4d89c96a5f5b3,8040932727800080,8ec8e8e894d4c0c4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.