Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1038419676390363DC28BF1E19E5FCD4C733951689382801C655C86E89EA4CB89BBDDF8 |
|
CONTENT
ssdeep
|
6144:zgAHL3wJVfiTbiAeQwPhqYZqrgNvmwvXRM2eMmIxTNWM50X8PXxBtpL5y6l4RMq2:PHL3wJVfiTbiAeQOZzLsa3U2eFtRsbbH |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c33c6898b7c31b3a |
|
VISUAL
aHash
|
0000242e3e7c7860 |
|
VISUAL
dHash
|
f4b048ccccc8c0c0 |
|
VISUAL
wHash
|
00002c7e7e7efcf8 |
|
VISUAL
colorHash
|
30019000400 |
|
VISUAL
cropResistant
|
c1f0f0f8bcb4bc3e,8244229696065082,f4b048ccccc8c0c0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1464 techniques to evade detection by security scanners and make reverse engineering more difficult.