Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16313D8F1A224A77F94C7C3EDDB316AB932A580DEEA220311C2FD871C19D6D86CC1A5D4 |
|
CONTENT
ssdeep
|
384:z39vODiQ+4gJAz132jFwnP3GbzPGl7NoSPoIWJoYzG6ZioMphfbqdwK8M4S5mjTz:zCT+4gAzS0vf7No9IW/EZVPM6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8ce30d3c33966c3 |
|
VISUAL
aHash
|
fdd3d39bffcfcfcf |
|
VISUAL
dHash
|
63363732831f9b9f |
|
VISUAL
wHash
|
99038193ffc3c3c3 |
|
VISUAL
colorHash
|
070010080c0 |
|
VISUAL
cropResistant
|
63363732831f9b9f,dcd76e6c3f171701,1770f880c0030323,17a68ec8828e8082 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.