Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T137B21F71E10C647E419792CBBB3A6359E39A8217DFE2012D8EE883D90796F91DC93319 |
|
CONTENT
ssdeep
|
384:Uk1O2teRHxAymktOWOcpOtOSO0pH4ZOX5QfjGKtt:Uk10Aymktb1p01zpH4Zw50GKj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fab181de6c4b13b0 |
|
VISUAL
aHash
|
ffff0000801cffff |
|
VISUAL
dHash
|
101c983125696196 |
|
VISUAL
wHash
|
ffff00000000ffff |
|
VISUAL
colorHash
|
07200200180 |
|
VISUAL
cropResistant
|
3018180c9c1c98d9,3125256169943892,98f7e79f66667730,b8b8f8e8f8f87878,cd4161c10938090f,022d52b292512800,02ad12b6b6914800,d9713125252d7169 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.