Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1038163235082685F430583C4A2E2BBA69666C416CEB54F00D75A4FDBF9D8FB1F07718A |
|
CONTENT
ssdeep
|
96:LEgRviRLy/lf+iQ0qfCsR3h6KWjdUtKSIDkLRu6/lTkgY:AgR6RLy/lf+iQ0qfCsR3h6KcygSQURuR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c96632d966333366 |
|
VISUAL
aHash
|
1018000018181800 |
|
VISUAL
dHash
|
30b22808b2b2300c |
|
VISUAL
wHash
|
819999999d9d9d81 |
|
VISUAL
colorHash
|
38000038000 |
|
VISUAL
cropResistant
|
30b22808b2b2300c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.