Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1004176B0501BA47BA0A3C2D9B27A7F1B35D6838DEA470701A2FD93980BCAD92FC06015 |
|
CONTENT
ssdeep
|
24:hHptGp1dc8ss978stTEEIxEIxE6lMok9R2tbOfzUoFR6IZOfwyOSZSZST6fuj62M:miI1tTEpauMokv2t4lhUvOSZSZSTobsG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0304fcf4f9730c5 |
|
VISUAL
aHash
|
00c7c3c7ffffff00 |
|
VISUAL
dHash
|
399e9e9e96961610 |
|
VISUAL
wHash
|
00c3c3c3e7e7ff00 |
|
VISUAL
colorHash
|
06001000007 |
|
VISUAL
cropResistant
|
9f9f9e9e96969606,626a4266466a6a60,0000060606060200,166969b39ba4a41b,00000c3232080000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.