Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A242EE623084752747D793DEAA35A358E3E38186CE361A4262F98B0F9FD7E41CD1246F |
|
CONTENT
ssdeep
|
96:vkGiLiXbDXuE8c0fvhwBp+BiphIJu8M50XePy4BN504DJP4T4likBw0AYIyp+qSj:vkAXPXv+nMtWSjwyJp+qwpgf40fMU4 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e6e71919cc664c33 |
|
VISUAL
aHash
|
ffffe7e7ff000000 |
|
VISUAL
dHash
|
8c084d0c4d311131 |
|
VISUAL
wHash
|
66ffe7e7ff000000 |
|
VISUAL
colorHash
|
1e0010002c0 |
|
VISUAL
cropResistant
|
4c4c4d0c4d101131,0000148c88868000,743c86c6a2816953,303032300030b2b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.