Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16A713F6FE8CE175A03D60199F45125DDB68A804C8BB386800CF4865C6BBF3B219BC39B |
|
CONTENT
ssdeep
|
96:EqRPxt/a/BxK7x+txOx2xGGzSvgsDMke4OVmY2fJkm2T:PPXyZxMx+txOx2xGnYs/eus |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
adad60a1871ba8d7 |
|
VISUAL
aHash
|
ffffffffff010000 |
|
VISUAL
dHash
|
5367367746970080 |
|
VISUAL
wHash
|
03ff9fffbf010000 |
|
VISUAL
colorHash
|
17201008080 |
|
VISUAL
cropResistant
|
7387663736674697,0000000000000000,0000010000010100,d35bc0063000c090 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.