Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18721371508054E7F893303B49BC1F514A2A6CA46F253694042F95ADF2BC4F98CEBF7D2 |
|
CONTENT
ssdeep
|
24:hWGfsuK6hX1ksfUq1Nbi1+42c4h3Y4hq9PZe25+7Ix:bEuMq1ZJ4n4hIn9PZeA+kx |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc14d7678b5aa02d |
|
VISUAL
aHash
|
0002df19038088ff |
|
VISUAL
dHash
|
4db4b6b3b21a5252 |
|
VISUAL
wHash
|
0046dfd98b8a88ff |
|
VISUAL
colorHash
|
010000001c0 |
|
VISUAL
cropResistant
|
b4b6b3b21a1a525a,c74fcee8f1d3c3c3,f0c48ecc968ecce8,4462f2bce1b1b19e,fc96929a9acbabca,75b4b6b3b31a1a52 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.