Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15C51422080589D37914395D8EBF56E09A1C6C348CB052D00E6F8DB9D2FEBD14DE566BD |
|
CONTENT
ssdeep
|
48:l+K9kWNniNgQ/b1gjVu9arLrmUxx/+lHwrFsMHIlAkQfykTQ57K7:QK9VEjmhua/rmUDsMHIlAmkUK7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a35c334c730d7f09 |
|
VISUAL
aHash
|
00ff0000ffffffe7 |
|
VISUAL
dHash
|
0900514d0000d04d |
|
VISUAL
wHash
|
00ff00ffffff0000 |
|
VISUAL
colorHash
|
07000000007 |
|
VISUAL
cropResistant
|
0c8049080044d0cd,0008113131310810,0000101010101000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.