Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E7C3D6A0B3403D3D609743A9E370B67173A3B185CB124640CAF5563A8AD7DACFE375A9 |
|
CONTENT
ssdeep
|
1536:sjEo7VEp7AXI52SqT2EpetEpqw4IWYYax9iE2Oo:sjRc7AXI52zTJ3qwTViE2Oo |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a449ffb569c33430 |
|
VISUAL
aHash
|
ff00000000ffffff |
|
VISUAL
dHash
|
5e7986e2948c0837 |
|
VISUAL
wHash
|
ff00000000ffffff |
|
VISUAL
colorHash
|
07e00000000 |
|
VISUAL
cropResistant
|
ded6260079596034,b46e008c0e332707,0946369ede965606,929ec796e2879cfc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.