Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T174D32170A8615D3351B7C2DCD3B19B4B72E59329C9630986F3F897A84BDEC91EC02E61 |
|
CONTENT
ssdeep
|
1536:aa8dr+BvH9TovB5fUt9uI2Q7DQFQB6DQE69PhZsXEaVTJhSsadNIQRbwXsk9Gugv:p7MaB6DmgGULrFJzdZOX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b4363b49cb09963d |
|
VISUAL
aHash
|
808606f0f15702e0 |
|
VISUAL
dHash
|
351c3ca6a7a4160c |
|
VISUAL
wHash
|
840607faf37702f6 |
|
VISUAL
colorHash
|
03218010000 |
|
VISUAL
cropResistant
|
c0c0c0c0e0a49eda,b23232b2b2d2b323,09b3766daae9ad2a,3315d2ccd9b059b3,95dd4525a42424a5,abadf494946cc8e9,351c3ca6a7a4160c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.