Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17491C913A3200B3947920BFC5B7131FEDA5F045C9B824FE932D486596395CDDC5B9B92 |
|
CONTENT
ssdeep
|
96:EN3PBnw/daPx9tTu2rc9ZwdSAjMqc+/bQcj7oz+OlibHlRCT:4PZwla59tT1rG73qc+kf+OlkW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a92bde1a2ad21b2b |
|
VISUAL
aHash
|
01030303031fffff |
|
VISUAL
dHash
|
ebc7cf8f8773988b |
|
VISUAL
wHash
|
01030343033fffff |
|
VISUAL
colorHash
|
03001000180 |
|
VISUAL
cropResistant
|
ebc7cf8f8773988b,6da6a6bf24989c56,54542bb625225e1e,ccc4809e8e80c4d4,b6e3c3c7c3c7c3fa |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.