Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11B64F9B1F3F01777410E93E5F9A6E950FBE520ED93C58DC8424C8EE8A181C7C69B598A |
|
CONTENT
ssdeep
|
1536:KIFyBYojdiETfCDb2znVyB2diESCEm6lQk2D8ILn3vgynSNJ/AZe80jNlv8M+QHm:wYz97/Y/6WH9+wAkeeM76 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9b5015aee0afe8ac |
|
VISUAL
aHash
|
ff0098f9b9bdbfbf |
|
VISUAL
dHash
|
d8d8316b2b696977 |
|
VISUAL
wHash
|
ff0000b98191bfbf |
|
VISUAL
colorHash
|
06400080002 |
|
VISUAL
cropResistant
|
d8d8316b2b696977,f9f9e1b3b3938fcb,0040406666602080,ecd2dfcd6a398f61,b637e6cf9f0d0d2d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4361 techniques to evade detection by security scanners and make reverse engineering more difficult.