Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1182372316811AE3B219BC2D673752B4EF3D6D649D7630A6567E8C32C0BC7E80CD39991 |
|
CONTENT
ssdeep
|
768:zjt+Imoik+blCP91oM3KTbmUXcJa/Pzb3oOq:zp+I79GM3IbmicJa/Pzb3oj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b90f46714e1c7947 |
|
VISUAL
aHash
|
00ff8f9fc9c8cf7b |
|
VISUAL
dHash
|
e33a3a391b9b94e3 |
|
VISUAL
wHash
|
008e8e8dc9cacf7b |
|
VISUAL
colorHash
|
07200038000 |
|
VISUAL
cropResistant
|
e33a3a391b9b94e3,0000066060604006 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.