Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T141D1B52BD71C262B07A306E17D10A7CED22B710CAB8296A85CB9C15C67B9715C2729E6 |
|
CONTENT
ssdeep
|
192:ZLMLB/qT/kxWU4EqG/NU9AbdwFmvES1Lo68NgR0g2:ZILB/qT/kxWU4EqG/NeAbdwF41LovgRE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
aa77d52a6a842f4a |
|
VISUAL
aHash
|
0000000000ffffff |
|
VISUAL
dHash
|
6f9e89899955f0a8 |
|
VISUAL
wHash
|
004001c1c1ffffff |
|
VISUAL
colorHash
|
020000001c0 |
|
VISUAL
cropResistant
|
89699d995554e914,200c3232320c0000,218e9929991955f8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.