Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1106130362000283B52574AD0B5F1EB2FB9EBC30CCD434995B6EC13D98FD6E81C8A2646 |
|
CONTENT
ssdeep
|
48:YOxNmTNMzXOcCQ2O2OIGnO1Ln0VC6IR+A+AcMZpzRrwSV037KncgdRn:TSbnOXID1Ln56IR+A+IpzRNV0dqn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a4844ac4b553bafb |
|
VISUAL
aHash
|
73f3d707a7030000 |
|
VISUAL
dHash
|
a6a724262686c347 |
|
VISUAL
wHash
|
77f7d787a7470000 |
|
VISUAL
colorHash
|
0b3c0000000 |
|
VISUAL
cropResistant
|
868004148ebcc0e0,c090800005060606,8c9ce4e4e4f484e4,a6a724262686c347 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.