Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B8B296B284D87A365346A7CB877BB727B196C415C60261C9C1D363AC2ABECD0DF1AD1C |
|
CONTENT
ssdeep
|
192:YpohHFBbVH3wWpjDu6KuWE8m4Fhjm4JDqSgXXom4hCU4AKm4b:YpohHFBBlZXellqSIXqhTFgb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c33c6d34a791a4c7 |
|
VISUAL
aHash
|
00187e3c3c3c3c38 |
|
VISUAL
dHash
|
ec71d0d8ccf0d0c8 |
|
VISUAL
wHash
|
02187e7e7e3c3c38 |
|
VISUAL
colorHash
|
00000008600 |
|
VISUAL
cropResistant
|
9aa45b5b63378882,6990b9562a2092c8,f172d292caded0f9,ec71d0d8ccf0d0c8,1e277f5924059595,7127071f3d6c6667,c7d5d9dc6f7acfe7,c4aaa0c6b3b2b686 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.