Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B33441A03D03A825309F06DF5227161D71D1DBC9E6636AD5A9F0E3389AF9C95FFE2240 |
|
CONTENT
ssdeep
|
1536:Pt186sJr731UhsIxX4wWOUSiO+CNIUE+UfN/4LSZwgRcbn9Mms6IcQpbr5Z62Y34:P0T72TityUy9Mp6WM+BEXQ1l |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fc2a572a542b473a |
|
VISUAL
aHash
|
00ffffffdffffffe |
|
VISUAL
dHash
|
dc00c03030423322 |
|
VISUAL
wHash
|
00ffffff9f008100 |
|
VISUAL
colorHash
|
07000000c00 |
|
VISUAL
cropResistant
|
0020003430432322,401cc4dcdc440002 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 112 techniques to evade detection by security scanners and make reverse engineering more difficult.