Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T191057561F341D4292647817B6BAFE9484136AF44EB06775BBC77C8208A8567D2F33B2C |
|
CONTENT
ssdeep
|
1536:p2BWIE2Lrqbz7bzHtbzbbzObzWbzFbzObzDbzHYbzbbz5bzpbzFbzcbztbzHzbzH:p2BW/r0yK8D05SXbtMVB4w1BVH7T |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d8ad73c699d0c91c |
|
VISUAL
aHash
|
ff81191919f8fcec |
|
VISUAL
dHash
|
614d3331313184dc |
|
VISUAL
wHash
|
fd00191919f8fcec |
|
VISUAL
colorHash
|
00007000000 |
|
VISUAL
cropResistant
|
614d3331313184dc,6831d48806e2a303,a3a3a596b4a94555,a686b2b2b0b2b272,3333a327531292e2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6763 techniques to evade detection by security scanners and make reverse engineering more difficult.