Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CC3362EC219717DF91B787D2E0227E6BF068F33AD59E9108666F08742FE7D606468360 |
|
CONTENT
ssdeep
|
1536:s2fki6oXS2TCP024kNwXSaBhltt9eU0C5PTKqZukYQ/BNwxFC36/:Ffj6oXSECs24kNwXSaBhltt9ebC5PTKz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b38bc96266cc8b33 |
|
VISUAL
aHash
|
fbe7e7e7e7e7ffc3 |
|
VISUAL
dHash
|
2b0e0c4d4d4d1616 |
|
VISUAL
wHash
|
81c3c3e7e7e78181 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
2b0e0c4d4d4d1616,e88c9cd64c4cd8a0,07f398d9c9595179 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.