Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BCB2757141E8BA2B82B377C1E7B47F2B3EC39259D9820B5C56D8B36C4BC2C66E445507 |
|
CONTENT
ssdeep
|
768:pvosGn+CG3O+GfCyGKMKGoeeGfoyGDASGepeGqve1:pvosGn+CG3O+GfCyGKMKGoeeGfoyGDA6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b645c9399cc3e2c9 |
|
VISUAL
aHash
|
0202f7c78787ffff |
|
VISUAL
dHash
|
74840527372f0e2c |
|
VISUAL
wHash
|
0202c7c78787c7df |
|
VISUAL
colorHash
|
07600180000 |
|
VISUAL
cropResistant
|
74840527372f0e2c,000008e4c4180000,4040404040404000,c1c3810505018001,0c2d2e9977da9b8b,7c1f000000001000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.