Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E9E1ED714019AD2F0473DAE0F7F7B716A6D5C600DE530A46C3F88B4E4AEAE54DC872A6 |
|
CONTENT
ssdeep
|
192:G4j7Nu1Q5m55O6koKSOTKEq3PN5MmBCDBXzBYCBdWBeLBjU:G3Q5m55OM3T3BCDBXzBYCBdWBeLBjU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bd78e00fc3871e61 |
|
VISUAL
aHash
|
ffcf8f0f0f1f3fff |
|
VISUAL
dHash
|
5a9b3b5e56727bdb |
|
VISUAL
wHash
|
eb49090f0b0f0f3f |
|
VISUAL
colorHash
|
07241000240 |
|
VISUAL
cropResistant
|
5a9b3b5e56727bdb,1c068b8393c3e363,a3f0f1f3713f0e39 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.