Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11B632523421979274437C6D130AA5B3BD1A6DD9BFEE70A010EDCCBF72AF9CA0705A159 |
|
CONTENT
ssdeep
|
384:C9NSakCstZzUMRr8nXxHD+YjOp4QFSVHFlTCxYrrYJ:C9kpR4nXF6YjOpSpFlTC6rrYJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
895ca372728f56a3 |
|
VISUAL
aHash
|
1818181840c0fbff |
|
VISUAL
dHash
|
6933333393840313 |
|
VISUAL
wHash
|
18181818c0ebffff |
|
VISUAL
colorHash
|
00000038000 |
|
VISUAL
cropResistant
|
565a9935353199b1,a4a280b2b2acaaa2,9082809a9abaaa98,139280b2b2aaa8b0,8280a28c8c82aa96,a28292ae92c68ea2,6933333393840313 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14649 techniques to evade detection by security scanners and make reverse engineering more difficult.