Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14C02307091957A37806382DAF3B57F1B92D0818DC6730F62A6FC839A17FAD51EC17905 |
|
CONTENT
ssdeep
|
96:+bqDikscwvtpVJ6JuCaJcJcJ6JEO56uMTg3DNn4y+yaEQhoWbI0trR:+bqytZ0nU660EOjx3xn4GaE0I0trR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ddd5366c6662488e |
|
VISUAL
aHash
|
fefefffffe180000 |
|
VISUAL
dHash
|
c09aba6850b04c11 |
|
VISUAL
wHash
|
78fefefebe100000 |
|
VISUAL
colorHash
|
01201030000 |
|
VISUAL
cropResistant
|
485ae6746e645942,d6d6c999d5952516,4840d7b4a9c3cbeb,00000830300c2000,c09aba6850b04c11 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.