Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D9D2C6937368237396630353E61E33D0E76680D84266225055EEC1CDB398ABAD7377EB |
|
CONTENT
ssdeep
|
384:zUdJpyopmJPtjt+G+cW93nM9e3LyCqZLI4ijeCOnEBNGgPWNB2ezFRRDZqx4P07P:zUdJpyopmJu7yUxOnEBsgM/HYxGmDj+S |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e96996963232c7c9 |
|
VISUAL
aHash
|
ffd9f9c1f9f9c7ff |
|
VISUAL
dHash
|
2333331b13339eb2 |
|
VISUAL
wHash
|
bb818981c989c3ff |
|
VISUAL
colorHash
|
0e600030000 |
|
VISUAL
cropResistant
|
2333331b13339eb2,b1b1adc9c9a5c1c1,40a020906798c827,8646464686696864 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.