Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11CA2613542CD2A6212271ADAF191EB1BB5C3D31EDF5BDCE1E3F8A3C54BC1D48AA42158 |
|
CONTENT
ssdeep
|
384:2nIbnRlC/zqWWYHAPnNmP7SCGY5LohB0+isXVlUDumQY+YfiZzFNSi8MN49gnfRE:2nIbnRA/zqJYHAsGCGY5LohB0z0muJYZ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e96a76975992944c |
|
VISUAL
aHash
|
e0e0f0d9f9ffffff |
|
VISUAL
dHash
|
0903333333120d03 |
|
VISUAL
wHash
|
c0c0c089f9fbe7c3 |
|
VISUAL
colorHash
|
060012001c0 |
|
VISUAL
cropResistant
|
0903333333120d03,0e072731130f2923 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.