Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11F13A560A1546A3F045303C9E376B77E22F1A380D746114987FD43BA5FE9DA8FC27A94 |
|
CONTENT
ssdeep
|
384:2bqE0tpobKT8SE16fvktvZFa4/YXlsai82IXk5pFz1L1AXrII3mrO66ZhhrUxfoA:2bqLtklafl2IYOrIIJ3dqA/L7cmVnDAD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93936c6c2ccce565 |
|
VISUAL
aHash
|
050c6c0c0c22000c |
|
VISUAL
dHash
|
29c9c929c8c6d8e8 |
|
VISUAL
wHash
|
8d2c6c3c0c727e7c |
|
VISUAL
colorHash
|
38018000600 |
|
VISUAL
cropResistant
|
945e5a325554f2ea,29c9c929c8c6d8e8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.