Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T112231B319CC4233706A323C177D7A647E294C181B61ACA8BDAFF834D52CDE95D63AB19 |
|
CONTENT
ssdeep
|
768:N44zr2KqqfZJJa0DkzQP/kj+7naxlOBlyAoqtQf1gLd7Rfe6OZFnHF5lgwdesnJl:N44mqXkKaO981Kr2Dt+wdRmu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9392c66c6c95b3c6 |
|
VISUAL
aHash
|
060e6e0e00003c3c |
|
VISUAL
dHash
|
ccd8d8d82b58f0e0 |
|
VISUAL
wHash
|
267e6e0e040c7e7e |
|
VISUAL
colorHash
|
39000018002 |
|
VISUAL
cropResistant
|
b0e8ccb865c6d5d7,ccd8d8d82b58f0e0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.