Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E4F272711150AB7F4297C3E6B7707B26938DC366CD9FCA0AD6FA82851BC2D65CE02B50 |
|
CONTENT
ssdeep
|
768:Ctp3s7g1g0gdg0+q+gy+n+S+I+BD+s+S+A+c+1+p+E+BB6aq6aa6V6aMT6aFT6al:6pL94+1XB6r1f7gUTB5cD4VLko |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c2d3186d6cfd9819 |
|
VISUAL
aHash
|
fffffff300ff0000 |
|
VISUAL
dHash
|
d0c8d8c787d0c4e5 |
|
VISUAL
wHash
|
ff7eff6000ff0000 |
|
VISUAL
colorHash
|
18000000007 |
|
VISUAL
cropResistant
|
0000000000000000,b2c9c8d8ccc78bd4,2090d640f4e4c5e5 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 56 techniques to evade detection by security scanners and make reverse engineering more difficult.