Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C9C56CE763C460F9D73683DAE53F224E2175791CAF08CBA081651F1C9FA8486B1379B6 |
|
CONTENT
ssdeep
|
49152:WhX6qDbe+OsqS8ZY7UQdLV7Duh7DSh7DSdiSgRtdovQeTYhaV80gODn:sDaF5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
90f0c36499cdde9a |
|
VISUAL
aHash
|
ff460f4f0f00187f |
|
VISUAL
dHash
|
a28cbc9a9804b3f8 |
|
VISUAL
wHash
|
ff440f5f0f00087f |
|
VISUAL
colorHash
|
31202010000 |
|
VISUAL
cropResistant
|
808082d2d2c28080,e9a99999a9a9a9a1,42b0564325231bc4,b01616269695958c,d9595a5a5858584a,0d4a6a4969303470,a28cbc9a9804b3f8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2703 techniques to evade detection by security scanners and make reverse engineering more difficult.