Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BB63B76AE0311D37419FB3F0E32527CA6293D352CAD257C0D0EDA26997CBDA19E4368D |
|
CONTENT
ssdeep
|
768:pyMPHXYAo66PbyJyoHCa9HC21igfA3BroRUM+udM6IMCbYpwLyCZ:pyMPIby3HCa9HC21m35kdE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9246ed69b216b5e1 |
|
VISUAL
aHash
|
000066040000ffff |
|
VISUAL
dHash
|
9ac6cccc9d1bc430 |
|
VISUAL
wHash
|
007076664409ffff |
|
VISUAL
colorHash
|
390020001c0 |
|
VISUAL
cropResistant
|
b87878f49cc8f2bc,0000000014c33736,9ae5c4cc8c9d1b25 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 202 techniques to evade detection by security scanners and make reverse engineering more difficult.