Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C813626175551A6B22B7C7D1F012EB56D4AEF74BC54F8DC173A802722FCFCA0A240BA6 |
|
CONTENT
ssdeep
|
768:SIbFbmb5UbcbpmZfJlJabvb/blb0CbsbzbEbygSb6XbAybA/bAmKgb5/WbVbgbhE:SBNV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e08f96434b347d71 |
|
VISUAL
aHash
|
20ffc3c3c04247c3 |
|
VISUAL
dHash
|
c4d4161793929695 |
|
VISUAL
wHash
|
20ffc3c3c14a57c3 |
|
VISUAL
colorHash
|
01000030080 |
|
VISUAL
cropResistant
|
cc96171793b29495,f0c4dcd08ac3c956,d0544f79a9db5717,70e087216d78860b,7efa8cc62424c500,25dafaeaeaca3580,c2ccc4d4d4cccb2c,d416179393b69495,47891939276e268c,4b993d5955594b43 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 61 techniques to evade detection by security scanners and make reverse engineering more difficult.