Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AEA11060A0489E379143D5C4B3E2AF1B71C6C643CA4A871592F283EF59E7E96CE41295 |
|
CONTENT
ssdeep
|
96:XCxb9PyNvN7Okplf/1kxzwyNrAmjllkm18BWo7:Yb9WpOkff9gzPAYlp2Wo7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d3dc006a27998d77 |
|
VISUAL
aHash
|
f8f4de9be7590d27 |
|
VISUAL
dHash
|
6084b03a4db3d9cc |
|
VISUAL
wHash
|
f8f4da98a3590d26 |
|
VISUAL
colorHash
|
07001000080 |
|
VISUAL
cropResistant
|
6084b03a4db3d9cc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.