Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E902A61BD31872B4074103EC6B3171FDDB16194866B14E9A29BC50DCA1E0A5C6EB7BAE |
|
CONTENT
ssdeep
|
192:eOTP4weGKtaCaBreS3MIBYjf9Xsq1UxuTKfhGCcm+ORy1xPVZbON1r:eO74weGKtaCceShB4f9cCUxuTK5j++og |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b33cdc42ec634633 |
|
VISUAL
aHash
|
000f0f6b6f6f6fff |
|
VISUAL
dHash
|
ac58dbdbdbd9d9d8 |
|
VISUAL
wHash
|
000f0f616b6d6d6f |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
ac58dbdbdbd9d9d8,3f1f1fbbb3b33f1f,61d0d8c4d4d0d0d0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.