Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T101727123B100C8295EDB5ACCF2D4AA48511ED342F63188CAB16891FF7BD4CF466967ED |
|
CONTENT
ssdeep
|
192:TneAdWGer6nxFY45GxhS3xxiMcnthWeNWbZfMmUU8VCoHnC:TneUWGer6nHtgMTfMmUFCoHnC |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dc0c2337e8f08fc9 |
|
VISUAL
aHash
|
000018d89c9cc0e0 |
|
VISUAL
dHash
|
b6f23232327a8c41 |
|
VISUAL
wHash
|
001819dfdf9ee4e1 |
|
VISUAL
colorHash
|
010000001c0 |
|
VISUAL
cropResistant
|
a0a2e2b2e0803333,31e89cd8cc04a4c4,7a78181c7c9c9989,f1d8dc7ab999d9c9,b6f23232327a8c41 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.