Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E9032B72B099B15D12559B81D9B0F3ABCB42C9049FF00E06D8528F8AFD46BB179F235E |
|
CONTENT
ssdeep
|
768:Ho42I42ZLWspvMso4EfAt4CY0Y3vwpwO4q4M4E4Ds4Z:52I42ZLWspvMso4EfAt4CY0Y3vwpwO4j |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8295391fca687ace |
|
VISUAL
aHash
|
007fff7eff0000e0 |
|
VISUAL
dHash
|
92d6cc84654c888d |
|
VISUAL
wHash
|
006fffffff000060 |
|
VISUAL
colorHash
|
11000048018 |
|
VISUAL
cropResistant
|
c2c069cc6a3b31e3,6d6cacd8c09dd1c0,409c99999d98c4f8,d5d5c4f2ed66670e,ad1f5f6e67e373f4,8e862622aab03079,82a24545456d7d7d,33b1c692b5a6ccc9,92d6cc84654c888d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.