Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CC717737D010440BE60359F8A754328CA99B534FCEE258A0F3F057A9A3FCDD66875AB9 |
|
CONTENT
ssdeep
|
96:Zz1P62uQlXrQB/gyh3g7R30t3g3+kkb34/Nue5aJxON1r:ZJPhllXrQBoG3o30t3g3+k/laXON1r |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b3cde6d8c0709c39 |
|
VISUAL
aHash
|
ff2f0f0f0f0f0707 |
|
VISUAL
dHash
|
ccdd7a3a1a5fcdec |
|
VISUAL
wHash
|
7f070f0f0f0f0707 |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
ccdd7a3a1a5fcdec,f08c8cce8e36363e,ce162f6fc9959211,5b5b8b5b1b6b6069 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.