Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D7637620E194AD7B82A382F5B7B5B77BA1D29705CB43530057FD83AA0BD6D4AFC23059 |
|
CONTENT
ssdeep
|
1536:AL0JbPQ9qaLwMPOcF3Aep9q2YMhZ1hJL691WUnu:ZQRPORU3YMH12QUnu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed4c129379439e33 |
|
VISUAL
aHash
|
9cf1f1f1f3ffc781 |
|
VISUAL
dHash
|
1927230713300f0b |
|
VISUAL
wHash
|
00d1f1e1e3ffc381 |
|
VISUAL
colorHash
|
07000048003 |
|
VISUAL
cropResistant
|
1927230713300f0b,0001010706070101,0040404141404000,2cb8e0e4e4e4c693,004003d4d42b8442,0b53f1faf8703331,8e8989c9d0929a38,35438bcce0c87979 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.