Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C1812171D4889EB746A1A2DC633B722DAA90C202DDC3069CE5FA435F1BDEE87D413189 |
|
CONTENT
ssdeep
|
48:cwfDEAHeRGOSzc2ru97x2JVPFlrPIEVXPJ0dAXOL/zOfzYlVjzwHzn+8zYiYzYgJ:R36SRR/DVB0iXsLOeQ+2Bqjwqjf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b130cece33336c8e |
|
VISUAL
aHash
|
ffcfc3c3c3d3ffff |
|
VISUAL
dHash
|
4894969e9e96480e |
|
VISUAL
wHash
|
e4c0c0c0c0c0f0c0 |
|
VISUAL
colorHash
|
07241000040 |
|
VISUAL
cropResistant
|
4894969e9e96480e,ddcdd25358b6a6c2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.