Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17BF2C877D3C0627B035342D12325B39EB396C3E9C7850A90A2EC935D9FC6D65AEB25C4 |
|
CONTENT
ssdeep
|
768:Ge19yp/44t2SoopvHo/gdhqe8Mfkd3WJq:E44t2Soo1/tcMJq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c392bd2d83c79692 |
|
VISUAL
aHash
|
ffe0f4f0e08000fc |
|
VISUAL
dHash
|
2000cdc889030200 |
|
VISUAL
wHash
|
ffe0f4f0c0c000ff |
|
VISUAL
colorHash
|
01000e00010 |
|
VISUAL
cropResistant
|
2020000212c8cdcd,33e3a767d1733b3d,856a4aa9abab9d02,004962aaa2a21210,c64a4cedcade96ac,80a280af27c08080,0000000000000000,02c8ccc889030202 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1 techniques to evade detection by security scanners and make reverse engineering more difficult.