Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11FB1C63FD2D88336171342EC76AE61CCE36B00588752CEDA5924855CA3ADA1149732DB |
|
CONTENT
ssdeep
|
96:Ai7VPuw/zXfJxtbSCyCRuozXB0yteLG2AqsnwIHxCsyK6dvorUxJGiwZPp0CXHET:97VPuwbxxtbSC7oozXB392sgI6xxciw+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b676ccc93630c1c7 |
|
VISUAL
aHash
|
ff1f7f07077f1fff |
|
VISUAL
dHash
|
246cc40d0dc07c60 |
|
VISUAL
wHash
|
17072707073f0f1f |
|
VISUAL
colorHash
|
07011000200 |
|
VISUAL
cropResistant
|
246cc40d0dc07c60,810e8e8acecc8c9d,25266c8ccdd64f4f,69265ecc5cd95e46 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.