Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F1510DFB90F1943E3801CB85B571778883764174CE520A34A3589E6DC1C9F79AC8CD8B |
|
CONTENT
ssdeep
|
48:+wycpcTO7rI1s5G+t8LFR9lVEhltWybfV6oEd6oEz8oWSYNyXoy8HgoyJ10opOTE:+J+gO/lGOIFb0zbtgzHHS75 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
87d8737758b2238c |
|
VISUAL
aHash
|
267f7f3f3f232320 |
|
VISUAL
dHash
|
ccf2f2f2724e4e4e |
|
VISUAL
wHash
|
263f3f3f3b232300 |
|
VISUAL
colorHash
|
06207000040 |
|
VISUAL
cropResistant
|
c912e6cd49923466,98f0f2e4e49e9e9e,d2d6b4a4aee86d4d,ccf2f2f2724e4e4e,9a1a1b1637373509,d993264c99b3644d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.