Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15B42A333A600DD294D9B9188F6C495899059D349FF3148C7B2A0A1FF7BC1DF12DA93AD |
|
CONTENT
ssdeep
|
192:+M3JXhKdJbKg/ES4FE12XBxF3twt3tzYMcnthWeNWbP4yfMmUU8VColL:0JbKg/ES4FEW3twt3tzf4yfMmUFCoJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e695ea498991bb91 |
|
VISUAL
aHash
|
f0f0f0f0f0f0f0f0 |
|
VISUAL
dHash
|
266464e4e627a727 |
|
VISUAL
wHash
|
f0f0f0f0f0f0f0f0 |
|
VISUAL
colorHash
|
0e000000038 |
|
VISUAL
cropResistant
|
266464e4e627a727,aaaaa23a3baa80ba,fcb37078fdff7f7f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.