Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F1333AF47842F5239AB3809760FF1506737E150FA80D4960E268EEDE75F485A70A7BC9 |
|
CONTENT
ssdeep
|
768:uQ/T0TQH7YFUSYjjcXu2qTRER9vPe0Vzc+b42NB2jIGrTnzq8QE12OlDlGYQZ/y:uQJc+2qTOR9vPegzQ2N0msQw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a40636b9b9b14d67 |
|
VISUAL
aHash
|
000000ffffffe7e7 |
|
VISUAL
dHash
|
d8e4e43b33070f0f |
|
VISUAL
wHash
|
000000ffffffc3c3 |
|
VISUAL
colorHash
|
12200030000 |
|
VISUAL
cropResistant
|
12a6124d4c0a92a2,1c3b33370f0f0f0f,c6d8f0e4e4e0e8f4,1111751111711115,0000000000000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 35 techniques to evade detection by security scanners and make reverse engineering more difficult.