Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C6421F2274887427078763EDA925939DA7A3815BCF370F4663E08B0E9FD6E42CD1245F |
|
CONTENT
ssdeep
|
192:vUzCXjLj/Tx6UhJ1nEITOATWE+a/wyJp+qwpgf40fMU1:vMMjLjr36YN5p40fMK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8706f8fb5da4221e |
|
VISUAL
aHash
|
ffff000000ffffff |
|
VISUAL
dHash
|
0ee2ccc4e88c0890 |
|
VISUAL
wHash
|
c317000000ffffff |
|
VISUAL
colorHash
|
0f001200041 |
|
VISUAL
cropResistant
|
10084816160e08b2,b4f8d6e983848306,00104c8c94901010,000204ccc8940000,e4e4ccc6c6e0fce4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.