Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FF53B43341957136A17683DED2B9B308A3DAA40FD342DB94E7FC41BD9F86DA0392164E |
|
CONTENT
ssdeep
|
1536:2p/nPdLN5sIYrDrlbeyqiCRcwcYKPM2Qy9Lnmf3eJgn6P1teM6h:2p/nPdLNeIYrDr0iY3cJQy97mf3eJq6i |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a54ffa1720ca5965 |
|
VISUAL
aHash
|
0000000323ffffff |
|
VISUAL
dHash
|
cdc6c2c6ceee0796 |
|
VISUAL
wHash
|
0000200367ffffff |
|
VISUAL
colorHash
|
06200018003 |
|
VISUAL
cropResistant
|
c692c6cece390696,9b93d6a531648a92,ac4949d1b6d6144b,3624a5a3a223a1a1,b2a635a5a633b2b2,b5b74a16b69695b5,cc61c6d6a2c6cece,a0d2b42c24629b2b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.