Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E5A3EDB0424020AF0BD3FDD068A2BF47A1B2C9E9E51F9DCD92AC59881FC1FA1D4D56E5 |
|
CONTENT
ssdeep
|
1536:vWPdkeI3iPiM7nS6iK+dfnIs1Ltsgx7FY7mY7gE7tK7LQ7wOn73hp+Uejv1b58qb:8E3iPiM7nVJhm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c6d6283116bed6b2 |
|
VISUAL
aHash
|
0470fcf4a460031d |
|
VISUAL
dHash
|
4cc26d6d6cc7c3f5 |
|
VISUAL
wHash
|
0470fef4aef0033d |
|
VISUAL
colorHash
|
31001030000 |
|
VISUAL
cropResistant
|
cececce6e2939726,c585cd91b9759599,d5d5d5d5d5d5d5d5,a4a4e5242664a5a4,aa36e66e2ed2bac6,4cc26d6d6cc7c3f5 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2813 techniques to evade detection by security scanners and make reverse engineering more difficult.