Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13D04EE60D0705AB701DB62D96274A76B3B8ADF0AC9D22BD106F9F31E5BD2D51ED2320C |
|
CONTENT
ssdeep
|
3072:Q3qvbaLY25+wPD9+YLnieG0OQpEWouaVYl1:Q3qvbaLY25+69+YLnieG0OQVou/1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9a12eda3756cc52c |
|
VISUAL
aHash
|
bf1c100004ffffdb |
|
VISUAL
dHash
|
70f9b1e9e8cd2b2a |
|
VISUAL
wHash
|
af1c040004ffdfdb |
|
VISUAL
colorHash
|
060010000c8 |
|
VISUAL
cropResistant
|
79f9b1e8eccc2b2a,3b13644856c496b6,391bd7ebca3527db,0616063430160616,3fcdde537fcfcf3f,50636963738c6373,8c34178b0b9ce16c,0c2c24253434d4b4,4ada534eda539696,99277d3475797969 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 2 techniques to evade detection by security scanners and make reverse engineering more difficult.