Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1713234B484A6CC771163A0D2DAB6DF1739D18209C9E74709A3FD9B6A9BC9D40FD13C12 |
|
CONTENT
ssdeep
|
192:9lAOmq5CN+EAorafAlhOj8Yw/V0eBrV0kWtl7CCN+FsoroffvhOjbAYwI0Ajf13j:9lAOmUuV0eZV0k2cl0AR+yLV0XjV0MnY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc3366cccc66cc66 |
|
VISUAL
aHash
|
1818181818181818 |
|
VISUAL
dHash
|
b232b2b2b2b2b2b2 |
|
VISUAL
wHash
|
38383c3c3c3c3c3c |
|
VISUAL
colorHash
|
30200010002 |
|
VISUAL
cropResistant
|
101ab6a5c789aa96,5a9ab3b6d2520286,b24d4d4d4d4d4d40,00cf4dcc012072c1,00cc4dcc802872e1,32cc4dcc00a972e1,32cc4dcc80897270,4b25256b09496449,b232b2b2b2b2b2b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1389 techniques to evade detection by security scanners and make reverse engineering more difficult.