Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T134524273F508353B0933D2E57625BB8FD086A129CEC65862E2FC876E16D7D92DC4221B |
|
CONTENT
ssdeep
|
192:FBMQjxKjFjXn4zFInvjmjpuAgqR5Pjcjp+UNzazvzQtzXUzCzNT+zOStzLuZ+zpJ:FyQVMn4zFInSuAxeQDRHzP |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
eb520d3ee01fe4e0 |
|
VISUAL
aHash
|
00e0f0f0f19999f9 |
|
VISUAL
dHash
|
0381810103333393 |
|
VISUAL
wHash
|
c0e0f0f1f19989f9 |
|
VISUAL
colorHash
|
01000008208 |
|
VISUAL
cropResistant
|
00c0c001490a3ec2,c080a0c4ea3416c6,9dcd4e87c3d1ece2,60a9acca8b4389c5,2925212d57131692,0381810103333393 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4571 techniques to evade detection by security scanners and make reverse engineering more difficult.