Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FE1231711855A837069382E2BA7A7B1FBAF6C200DB670356B2FC875E0FE6C14DE47211 |
|
CONTENT
ssdeep
|
192:ckwEYaEjWL4R4P6m2OgRzsh2/6kYlEnw/NNwSm9q9SgX35S9Wo6rEh:cpSEjWL42PT2VzS2ykY+nw/NNwSm9q9q |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9163274d5e0df0b6 |
|
VISUAL
aHash
|
002c7e3c3c7c3c2c |
|
VISUAL
dHash
|
49c8d8d0f0f0f0cc |
|
VISUAL
wHash
|
00287e7c3e7e3c3c |
|
VISUAL
colorHash
|
18001200088 |
|
VISUAL
cropResistant
|
766aedd6b1e0fcff,34a4c0e0b2e2d8d8,5b2f87c7f3f9fdff,49c8d8d0f0f0f0cc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 4 techniques to evade detection by security scanners and make reverse engineering more difficult.