Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16C437530B16958B7114383C99BF4AB1E72D2D28ACD1307619AF4931F6BCBDB6FC06259 |
|
CONTENT
ssdeep
|
768:Ve4uPDcxD6E3WGENkVvsa4GVVoQf16MbHWI3xzW9qgBh3fE+5F06q:c4uPDcZ6eWG7lsa4GVVhzTM9XJ5+6q |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92b0e9eda3929a65 |
|
VISUAL
aHash
|
ffd10c2c00180001 |
|
VISUAL
dHash
|
23a7ad6ccc716869 |
|
VISUAL
wHash
|
ffd57f3e041c0031 |
|
VISUAL
colorHash
|
03006040000 |
|
VISUAL
cropResistant
|
0b23230b202f2021,a686b0b2a02b2baa,40c280d0eccc80c2,b7ad6c4ce2796869 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 3 techniques to evade detection by security scanners and make reverse engineering more difficult.