Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F481B53FB390A7342B7202A4B82975CEE645000EDB6291D71DA5C4AC13F7B759B764CE |
|
CONTENT
ssdeep
|
48:r3YS57vtI6x/XpzHkZgFlbZ9uP5WhjHnoeVOBQVS5AKqjIHxyr9Z7pLORg/vr6J:rxFp/ZZgRWV6QyA/cRyr/79qg3r6J |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b7e4c83c3fc8c825 |
|
VISUAL
aHash
|
ff3fff0703ff7fff |
|
VISUAL
dHash
|
76e6865e5eb9edc0 |
|
VISUAL
wHash
|
1b17370303071f7f |
|
VISUAL
colorHash
|
07000000c00 |
|
VISUAL
cropResistant
|
76e6865e5eb9edc0,03279c9ce5cc9f1e,161ece949a8d8e4e,020dedce9e8ce97b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.