Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T147D140B0A085B63B01DBC7D1DF32676E32D8C2D5DA87271523FA83A44AC6F5EED16441 |
|
CONTENT
ssdeep
|
96:w2IeuJJ1cBUWoaX0arVMoFkX4g8jQLqyEKnhtaI4+4+4+4BBeKB:wveiJ1GNRkIgwQp4+4+4+4BBeKB |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e80b0f6d8d4e4e1b |
|
VISUAL
aHash
|
00c584ffffc0f0ff |
|
VISUAL
dHash
|
621d2ded959505b9 |
|
VISUAL
wHash
|
008185ffcdc0e4ff |
|
VISUAL
colorHash
|
03000c08000 |
|
VISUAL
cropResistant
|
8282c2ea6ae28282,3539ed98959505ba,626272e2738fcb30,91a919292d352565,e9e96133aeb46564,4cece5b4d3e9f561,b038a6a6e262e6e4,83137339b9b9f959 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1 techniques to evade detection by security scanners and make reverse engineering more difficult.