Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11C13A5F0661021B706A799D8BD763F4AB2ABD25DC9730609A7FCCBC95BE3C91DD12420 |
|
CONTENT
ssdeep
|
384:jQVKfzDPw3PUsJWWzDPw3PUsJ6eiMqTC6xTVLlq2D1ZRBTKRTK0lTKZTKbTKNmZQ:HuUs2Us67jkPeydgUsA6/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9318a86ae66dec6c |
|
VISUAL
aHash
|
000e0e2e0e0e0cff |
|
VISUAL
dHash
|
181c5c58585858dc |
|
VISUAL
wHash
|
0c0f0e6e0e8e0eff |
|
VISUAL
colorHash
|
39000000007 |
|
VISUAL
cropResistant
|
0b16162c2cd938f2,0000220c0e334b45,9094b2b2ceccb292,5c5c1c5c5c4c4c5c,050b0b1616ac18f9,1c1c5c585858585c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11986 techniques to evade detection by security scanners and make reverse engineering more difficult.