Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T158721B7421113B7B124382F6F620BF5A73E99349CB678654A3F8C35A4FEEC84CD4A256 |
|
CONTENT
ssdeep
|
192:XM84NahMyi2txZQ5QYk9GCn90Cn908UJKx6G9rsWBeCfyEUdPYKUEl:XsH9k9Gs90s90hWBeCqEUY9El |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d02fc59a61e49be1 |
|
VISUAL
aHash
|
00301800083c7e7e |
|
VISUAL
dHash
|
c6e070a5b9f8a8a8 |
|
VISUAL
wHash
|
203c1e044c7efe7e |
|
VISUAL
colorHash
|
39400008000 |
|
VISUAL
cropResistant
|
d9e62626b7a796ca,fff7e6653456b7b6,96366b33cbcdcc8e,ab8b5d55141c3423,7772e62c64eca9c6,c6e070a5b9f8a8a8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.