Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B3920853CC26624F712542D0B44E3B1499CADD3F86B2CE58E4FBE3D0AB758A4D72A264 |
|
CONTENT
ssdeep
|
192:aU9gL99f3abBzJdtVbnQ4cKuweuvfGnw2H:d9MX/aJHlbBvC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e88ca9a356c76d1a |
|
VISUAL
aHash
|
fbd9d8f800e3edc0 |
|
VISUAL
dHash
|
97b3b5a0391b0b99 |
|
VISUAL
wHash
|
f3d9f0f000e3edc0 |
|
VISUAL
colorHash
|
11680000000 |
|
VISUAL
cropResistant
|
f8383cbcfc7cfe7e,607070b0b0b8f8f0,b1b3b268e8391030,ece46b3996909493,17d7ebe6ed73a6cc,05c493333333b133,6c49cadc9eee6e4e,97b3b5a0391b0b99 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.