Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BA13826171593E7B01A393E63761678BB3F2C186CB271A1D62FAC39C0FE6C11DC62664 |
|
CONTENT
ssdeep
|
384:Iva3ZmSCkr8N828X8+D9hMMn7Tc7YXohwj5h6QtOEKGKVwFKkodKSYKmPKtKaUcY:qa3ZtFD3MR7Y9jUExe+YGbgbaga |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d3f71c0820829dff |
|
VISUAL
aHash
|
7ce0eee8e0181818 |
|
VISUAL
dHash
|
814a5ac801f0e033 |
|
VISUAL
wHash
|
fff8eee8e0181818 |
|
VISUAL
colorHash
|
30000008088 |
|
VISUAL
cropResistant
|
5ada085ad2c6d618,d9f2c4d4c8d46159,0c04565656565646,2a2b2b58542b2b2a,814a5ac801f0e033 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.