Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D2B163214100AD2F29D3D9E99EE2FF0A4751C755D5070A99A3C59ADE4FCDEB8C88E360 |
|
CONTENT
ssdeep
|
96:O+t00tSv9fEtTPcgtAatDa74x6i4qrjRC2Pm0G9I5KhPr:B000v9ctTkgdVacki4qhK0EI0hPr |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c1f49788e95f4989 |
|
VISUAL
aHash
|
7f7f787878383c38 |
|
VISUAL
dHash
|
d3c4e2c2e3e160c0 |
|
VISUAL
wHash
|
7f7f786070383838 |
|
VISUAL
colorHash
|
07200018000 |
|
VISUAL
cropResistant
|
d3c4e2c2e3e160c0,4e4e76a6b3726251,3414949414988c46,584464a6c8f4e403,0c00030c00020107,4e40697992e1e84d,52312549230b0b0b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.