Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T136234730A781063F55738BE6F7A5A73460FECA4AE64BC959F2BC419503CEC156B23B90 |
|
CONTENT
ssdeep
|
768:zeH6W/1hqwS0SDfYRElDfYRElDfYRElDfYRElDfYRElDfYRElDfYRElDfYRElDfo:4rI4l |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ac41c3be93cb6cc1 |
|
VISUAL
aHash
|
ff000000ff97ffff |
|
VISUAL
dHash
|
2992d2d22427271b |
|
VISUAL
wHash
|
bd000000ff81ffff |
|
VISUAL
colorHash
|
0fc00000000 |
|
VISUAL
cropResistant
|
69696980093d0040,361027272712331a,9e9e92d292d2d292,93d299978153a747,3e3a929eac7286a6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.