Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E1A2FB705091AA3B16C3A3E0A7357B1BB2C1C34ACA23171697F9835E4FDBE45CD4AA31 |
|
CONTENT
ssdeep
|
384:OAvqeyW9Gs90s90dSewgNa9GiNk9Gs90omcI:OG3As6s6WAXAs6GI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c513ecbf0ba4b0ac |
|
VISUAL
aHash
|
ff00000038fff3f3 |
|
VISUAL
dHash
|
e0e8d0f0e8062727 |
|
VISUAL
wHash
|
ff0000003cfff3f3 |
|
VISUAL
colorHash
|
07c01000000 |
|
VISUAL
cropResistant
|
e0e8d0f0e8062727,3db333deefffbffb,64703028222e1830,7e7e7f7bf9bd70f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.