Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C4A3F7E963E8A3F4E006F7F8D62364B57A4A24F9BB42C664C3E45E50A95246DCC49CC3 |
|
CONTENT
ssdeep
|
1536:k9zjNuy9n44LyuG7YKIkF9zjNRg00kic7mbRpS9tRzJH6h:QBuyZyMK5BWv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c2e92d3c96e16996 |
|
VISUAL
aHash
|
0000787e7e7c0000 |
|
VISUAL
dHash
|
9270c0ccccd0d0f0 |
|
VISUAL
wHash
|
003c7e7e7e7e3c00 |
|
VISUAL
colorHash
|
380000001c0 |
|
VISUAL
cropResistant
|
4a4a3696c6963b19,cb43594b5b5ab6a4,7cf0f2f6f7fbfafc,9270c0ccccd0d0f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.