Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B9921FA35014263B401272C9EB69EB24F3D7D169CB0582C2A6F0B31F975BF249E72E5D |
|
CONTENT
ssdeep
|
384:hwJykZZwh+yQneQ3QYxB+K+QnZzDArvW5XjcbtxM/SHUNrlW/flIAJOFSig:cykZZw4yYeQAYxB+K+QnZzDAre5Xjcbn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bf6a6b8c80959595 |
|
VISUAL
aHash
|
0100ffffffffffff |
|
VISUAL
dHash
|
6141406530707070 |
|
VISUAL
wHash
|
180007bd1f1f1f3f |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
6141406530707070,000054b2b2300000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.