Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B351EE701064BE73A1CBA5E46AB98B1A31DAC352EB03131456E4E3F90ECBE9CDB31581 |
|
CONTENT
ssdeep
|
48:NrDt8RWcty/6/cvixyHe/lnyF36nZ6E2qbA8lp+eJS:NrDt8gcty/Sqix5ly96sEd08lp0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d89a6249c47e73d8 |
|
VISUAL
aHash
|
d15d5c5e5a1890e0 |
|
VISUAL
dHash
|
b1b9b8b2b2b223a6 |
|
VISUAL
wHash
|
d1dd5e5e5a1a90e0 |
|
VISUAL
colorHash
|
06406000000 |
|
VISUAL
cropResistant
|
b1b4b4bc989898d8,495159637653e706,ccccccdc9db9d978,26e6e0e4e4d4d4d0,e2c4c78381838686,617171d1d151c7ce,7f77737373272767,93b3b284cca48e0e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.