Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T176427033A500CE2E8DAB51CCF6C49649525EC345FB3248C6A2A491FF7BC4DF069A939D |
|
CONTENT
ssdeep
|
192:Pti0YcycDchGLNQNONhcNojhAxnMcnthWeNWb2dSzalhVfMmUU8VCo8k:ocycDchGXqw+VfMmUFCo8k |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f2d25a56dad20a1d |
|
VISUAL
aHash
|
ffffffff00000000 |
|
VISUAL
dHash
|
310f0e0c044474a5 |
|
VISUAL
wHash
|
ffffffff00000000 |
|
VISUAL
colorHash
|
06007000000 |
|
VISUAL
cropResistant
|
4939160f080c0c0c,0101010101010000,0080258ecaa60100,2426c4445765a521 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.