Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FD826321F350313F09930391AF69237E77A68746D1115D68CAB892EC0BD8D0DFDBBA49 |
|
CONTENT
ssdeep
|
384:W7p4cIIiT/v8Qh3NT8WilWiXR5pmlZ4iw9zhhaP:WRIICn2TlTXOhP |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ad47fd92107cd22c |
|
VISUAL
aHash
|
002020001effc3db |
|
VISUAL
dHash
|
c4c7c7c7fcab3333 |
|
VISUAL
wHash
|
002171013fffc3df |
|
VISUAL
colorHash
|
020000001c0 |
|
VISUAL
cropResistant
|
6a851537c4e5e51d,f0003b2b2b33332b,a0808005338280a2,c4c7c3c7c7e7eff8,7feee6ceb2b2b3cd |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.