Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T156835222680F056FB217C3D592F4FAA7DD91CD0ADE700E40DAAA9FCAC791F11BA75118 |
|
CONTENT
ssdeep
|
768:YhFoqAXdZer04V9DLJVB7znbZlHKGaq0eGQwQX2YkXwg6yOOd7:Ud64V8d7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d079036760872fde |
|
VISUAL
aHash
|
60489cdfc0187e00 |
|
VISUAL
dHash
|
d49038babc60c8c5 |
|
VISUAL
wHash
|
605cdcdfc41c7e30 |
|
VISUAL
colorHash
|
32200038000 |
|
VISUAL
cropResistant
|
02120e2e2e2e1202,78c6c6c8989c8cc0,f0cececc8c9c18c0,78c6c6cec08c9c98,9f48f0d8e687d2c0,18c8f078f8e62430,86a6a6b6969a9a9a,8011080800000000,d49038babc60c8c5 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.