Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1902486A1516818BF04BB6BD1DF3853277692D14ACE4622C2D3F6C36C26EAC81DD93397 |
|
CONTENT
ssdeep
|
6144:OrZiTfZiPuj0XHypgUa6gGuvT+lXDU9zNz/MHd6rte3aBrER6kSFYQFW5rtNTpRl:OrZiTfYPuj0XHypgUxNlXDQzNz/MHd6I |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ab17e9c80716ad35 |
|
VISUAL
aHash
|
7b07070707fbc383 |
|
VISUAL
dHash
|
c7df2f6f4f978f0b |
|
VISUAL
wHash
|
3307070707ffc3c3 |
|
VISUAL
colorHash
|
06000000006 |
|
VISUAL
cropResistant
|
c7df2f6f4f978f0b,d2516964ccecd9d9,238b9b9b999999b3,45110cb2b2300955,cdcd32a6a6a66664 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.