Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C27382F10518653F408766C0A77CA726B3D6D284CF0A0A90E7F4D34ECB8BE95DCB665A |
|
CONTENT
ssdeep
|
768:VLvpdGLN4OvNZOXDFibeqF0ATFcvxsYBIvfONHsY/y7vfjGs:HqF0ATFcvxsYBI2HsY676s |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
80fefb83ec037454 |
|
VISUAL
aHash
|
ffff000303072fff |
|
VISUAL
dHash
|
0c48b4b7b6dcd92b |
|
VISUAL
wHash
|
ffff0001020707ff |
|
VISUAL
colorHash
|
06c00200040 |
|
VISUAL
cropResistant
|
5c0703010c4d0c00,b4b7b696dcd9d923,b4b4b7b694dcd9d9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.