Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17C63962250E55BFB11E3C1EB7670EA19D6CAC64ACB374E9593E8C36A4B97DC0CD21390 |
|
CONTENT
ssdeep
|
384:vDRPR1+IqGX2nWXNvivoZgvJ7AliLcrmtcPuu6Adjf5sFX1VRSffTV0MzRZvWm96:vDRP7+IRiAZiWlnylubjHdvW0/CAu3h |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9616e929ed699269 |
|
VISUAL
aHash
|
00060e060e0600ff |
|
VISUAL
dHash
|
95ecccccccccdab2 |
|
VISUAL
wHash
|
003e7e0e0e0e0fff |
|
VISUAL
colorHash
|
1a006000040 |
|
VISUAL
cropResistant
|
aeaaa2a0aa328ae2,5b808003d85c8090,95ecccccecccccda |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.