Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CAB3963086F1A93B019792D162B06F6F73828748FB572F4666FC83BA0ACBC91DC5B554 |
|
CONTENT
ssdeep
|
1536:Vdn9+XN06TNMoB+89Tg89rhZbnsI66OnZuTyeba2cZohS45:Vf3Mv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
df9df813e05488d1 |
|
VISUAL
aHash
|
9d9d9c9000088cff |
|
VISUAL
dHash
|
393b316469393431 |
|
VISUAL
wHash
|
9d9dbd94081c80ff |
|
VISUAL
colorHash
|
0e600600000 |
|
VISUAL
cropResistant
|
181c2c6034343424,f0f8f8e8f8f0e3ce,36169317174c0e2c,7979393030343311,a2c02b2b4d158880,38e08080c040607b,393b33306c793934,f2f2d6d6d6c6a676 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.