Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13B03C57390C9523B172B0FCD9636B37A72B7050DD5460828A2F903AF97E6ED8A52FC45 |
|
CONTENT
ssdeep
|
768:gkhcV2IiYhJ91Y7PQbBZ5ms1maWMvC9CXtDDwJIhrlkZEZFXBdOobOsqECG0EjI:gVPVZ5ms1maWMBtDDwJIhrlJXBdOobOV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d31cea0ce9c895f2 |
|
VISUAL
aHash
|
31042e0e0e06e0e0 |
|
VISUAL
dHash
|
63bcccd89c1c8488 |
|
VISUAL
wHash
|
ff0e6e0e4e0ee0e0 |
|
VISUAL
colorHash
|
39c00008000 |
|
VISUAL
cropResistant
|
d19393d35e59199d,84839ad8f17372f4,9098b4a2c3d87167,a6a0632e81898996,63bcccd89c1c8488 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.