Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EF63A63090845A3E0597C3D4DB307B2AB393C38BDB2743999AF18759AEE3D89DC47598 |
|
CONTENT
ssdeep
|
768:CRDgDSRTLyjGUEoBfrlrlUTHEo2fF/UQjLHrnryFihpCm8tYARaARq:ucSY3EojrsEoOUQjLHrrlp+5M |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
edcd9332c66c3096 |
|
VISUAL
aHash
|
ffcbc3919381c3fe |
|
VISUAL
dHash
|
61133333271f1f46 |
|
VISUAL
wHash
|
ffc38381838183fe |
|
VISUAL
colorHash
|
07242000040 |
|
VISUAL
cropResistant
|
61133333271f1f46,2f9e9e9c1379b535,e9e9e9eddff0f06e,791bb77b79371616 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.