Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1195322A07E03A816319F41DFD21F590D22D0FBCDDA526AD1A5F09335ADB6CA0BFE1294 |
|
CONTENT
ssdeep
|
384:dz627D1mU0+7/8/jLRaZVsgZi0+7/8/jLkcMF7YI5V1YIePKH2W2eE6+2u:vDQUx8/vRa7ix8/valYME6+L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0394e4e4f4d4d74 |
|
VISUAL
aHash
|
00cfcfcfc7fff7f7 |
|
VISUAL
dHash
|
72189e9e9f060606 |
|
VISUAL
wHash
|
00c3c3c3c7c3e3f3 |
|
VISUAL
colorHash
|
0760000a000 |
|
VISUAL
cropResistant
|
9e9e9e9e9f062626,0832323232343408,e78b9393b1256fbc,dcdc643a1dbd9e0b,b293838307676605 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1560 techniques to evade detection by security scanners and make reverse engineering more difficult.