Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C92265E0E4A0DD37075385D8A7F67B2B3271C345CF010D9853F853AA5BCEDA08B22999 |
|
CONTENT
ssdeep
|
192:Qk8jMzHOLLfoPEdrzO2vgSWj/pzvrhrxrhrz8F:Qk8+yLfoM5zu8F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c7b8e7a4e398c618 |
|
VISUAL
aHash
|
ffff000000303030 |
|
VISUAL
dHash
|
080a696962646468 |
|
VISUAL
wHash
|
ffff3c2c303030b0 |
|
VISUAL
colorHash
|
010000001c0 |
|
VISUAL
cropResistant
|
0800080c0c200808,dcf4e43179f2c2a4,a422a98d9e9d9596,da18dadadada18da,8000808080800080,8000808080800080,2080808080800080,8280828282828282,6a69696264646468 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.