Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E3828733F290713B1EA302C12B62635DB3FA854196411968CDBD934E47D9E8EEE3BD46 |
|
CONTENT
ssdeep
|
192:cVuTqu9oYWuIjIIuCwb2gHTbbx+1rjD7Yp1ojx4YRL3JlCzdKSY22fLdxU9L8Mo7:1OuIjIIuNSgHXbshMpu4YbSgO9eOH4z |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a842ff113df2016f |
|
VISUAL
aHash
|
00202000007fffdb |
|
VISUAL
dHash
|
cec7c7c7e79c2b33 |
|
VISUAL
wHash
|
00707101017fffff |
|
VISUAL
colorHash
|
01000008180 |
|
VISUAL
cropResistant
|
ec5d93d2b655447d,5a4eee5555628756,9f9e002b23332b33,434bb26424313424,018080a280922b2b,cecfe7c7c5e3ef9f,40066169124db2b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.