Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1530245705045A937019783E6AB728BAFA3E5C345DEA71B1263F8C35D5FC7C9ACD12109 |
|
CONTENT
ssdeep
|
192:cgoBcP44jvmZ/btRbVmrqKBs2xuv2/uv2+Auv2zu4QShiI9p:UB244jv0/ZR6Bs2xA2/A2+AA2zJhbv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8562fa5ded32a125 |
|
VISUAL
aHash
|
003f0703030707ff |
|
VISUAL
dHash
|
29ffdeceeafe7e34 |
|
VISUAL
wHash
|
003f2f07030f0fff |
|
VISUAL
colorHash
|
02200030000 |
|
VISUAL
cropResistant
|
ebffcfeafafe7e30,0000029494230000,ffffe7e7f47f7f3f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.