Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C0F320A0E5F1043A109F72D2FAA4E701E383A346CB9243FF72F593599F5BD90A85B548 |
|
CONTENT
ssdeep
|
1536:bXkcauV9vGp7C/SspzjnNkKjSeqhmbBgGfLbGm3AKBbwfdhbhXPQ37mExUgT/qPz:br9v/4jWuFLbdR22+MNyEL+tC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc53533446b969b8 |
|
VISUAL
aHash
|
0000dbdbd3dbdf00 |
|
VISUAL
dHash
|
cc343336363632b4 |
|
VISUAL
wHash
|
0000dfdbdbdbdf00 |
|
VISUAL
colorHash
|
06000000180 |
|
VISUAL
cropResistant
|
3333363636363236,2ccccce4cc333313,10c0c8c050000182,83b3a3838f838b6b,df4f1f898d9d1555,dba424c3e6a6e118,92a1e518ca3282c2,66d1d06660000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.