Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BA437F706082673F20D3C3EA77B56B1BA1E5C349C7275B5B93F983A80BE6C91EC52158 |
|
CONTENT
ssdeep
|
768:P0a17sWsbsjcevLwi/bT6/Sqt3WlEVx8JBSBvB5J:57sWsbsjfO1p |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cd679c32383398b6 |
|
VISUAL
aHash
|
38783800007e201c |
|
VISUAL
dHash
|
e263e2cf16c0c5b0 |
|
VISUAL
wHash
|
1e78782083ff781e |
|
VISUAL
colorHash
|
08200038000 |
|
VISUAL
cropResistant
|
3031061312469456,f3b09b9459595b5d,33f2ccababab8cee,e263e2cf16c0c5b0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.