Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12FE29F31C929CEBB0642E3FC91306E6F62E1A9C2DD23DB66B7F5D3D54B80C859D29804 |
|
CONTENT
ssdeep
|
192:q9sBYKhL8zVu0mqhXDzFKGWKPdkTO4qBBTTOFCBotHKaEhD:1NUVu0DhXDzwfKOTOb/OCBja2D |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e5939c996666619c |
|
VISUAL
aHash
|
ffffe3e3ebe3d3d3 |
|
VISUAL
dHash
|
0c0c06061a1aa6a6 |
|
VISUAL
wHash
|
e7c3c3c300000000 |
|
VISUAL
colorHash
|
070010000c0 |
|
VISUAL
cropResistant
|
0c0c06061a1aa6a6,17736949d4d52b0f,09c6c1c1f0385825 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.