Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T148532A30B131BC3843FB58EDB3AD6A46A183CA09D9C64AC4F694295D67C7CB536037B8 |
|
CONTENT
ssdeep
|
1536:aaWd3aMTOf7MTMMTapwaMCBTwJMCBAYaMCBUYJMCBRVN2/y9dGXDiJZBlvy40hxD:aavMTODMTMMTwwMwQYRYrN2aDSw0Ea |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
99dc2532a3e076e3 |
|
VISUAL
aHash
|
ff3cbc3d1d000000 |
|
VISUAL
dHash
|
313030307b31f2e3 |
|
VISUAL
wHash
|
ffbefebf1d000000 |
|
VISUAL
colorHash
|
0e200038040 |
|
VISUAL
cropResistant
|
d53030303030313b,41f0f17800000000,303030317931f2e3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 119 techniques to evade detection by security scanners and make reverse engineering more difficult.