Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11E03957852DCB6AF2183C7E5C732562A739AE564FA37424097FDC7A89BD2C99CC03940 |
|
CONTENT
ssdeep
|
768:B0dlbdruUnYUnhPiYwCbAt2SX97kpmecY8HmdKvdj1iFd+Qi:B0d9drmaPMCbAt2SX93HmdKvh1iFd+Qi |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8d10bb24fad4ced4 |
|
VISUAL
aHash
|
7f0838181210ffff |
|
VISUAL
dHash
|
f473f2b6f6e6e63b |
|
VISUAL
wHash
|
7f0838181031ffbf |
|
VISUAL
colorHash
|
0ee00008000 |
|
VISUAL
cropResistant
|
a4f67b7272727212,d5d5dede565686d6,dc3c7e7ef081c0c0,967672c676d4233b,999c9e94b6dc1692,821966071fb34802,078180a0b0b0b0b0,f473f270b6f6e6e6,5b97afdfbf7fffff,23331fc7c3d1d4d0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.