Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T196127323E600CD2A4D9746CCF2C4A688465DC345FB3058CA71A491FF7BC4DF1A9A979E |
|
CONTENT
ssdeep
|
192:3jcEdVh/4K1FFAFxz02xsEMcnthWeNWbWfMmUU8VComIR:3jc4VhT67fMmUFComIR |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8101abab1d376b3b |
|
VISUAL
aHash
|
007e6e3e7effffff |
|
VISUAL
dHash
|
c8ccccccd008c000 |
|
VISUAL
wHash
|
002424041cffffff |
|
VISUAL
colorHash
|
06442008000 |
|
VISUAL
cropResistant
|
c8ccccccd008c000,2bbf2fbb33abbb2b,a49218065751d6d6,7e3938dbda681200 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.