Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EB732022680E056FB257D3D592F4FAA7CD91CD0ACE304E40DABADFCACA91F11B675118 |
|
CONTENT
ssdeep
|
768:YhFyquoMr04V9DLJVB7znbZlHKGaq0eGQwQX2YkXwg6yOOd7:ULX4V8d7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d8912766f4850ede |
|
VISUAL
aHash
|
005cdeffd6002c00 |
|
VISUAL
dHash
|
d49038babc214965 |
|
VISUAL
wHash
|
007efeffde003c01 |
|
VISUAL
colorHash
|
39200038000 |
|
VISUAL
cropResistant
|
78c6c6c8989c8cc0,f0cececc8c9c18c0,78c6c6cec08c9c98,9f48f0d8e687d2c0,18c8f078f8e62430,86a6a6b6969a9a9a,d49038babc214965 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.