Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E1245550F2E29C32315F81E2A4B467090192FBBBC7411BC767B146B5EBF58BD384E299 |
|
CONTENT
ssdeep
|
3072:IRe0cvSI4BSYogIfa6mzOqE6FpD4Sna55glyaLLrIMWkYBd1eOp5+MPOWznRQB7c:IBCaT+e4c5+n |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8770705f0f7c0f70 |
|
VISUAL
aHash
|
007fff3f3f3fffff |
|
VISUAL
dHash
|
00a440505050a0e0 |
|
VISUAL
wHash
|
00003f3f3f3f073e |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
8000c082a2800080,86c050505058a0e0,4145808280c02120,0f0f1b4b5b4b534b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 50 techniques to evade detection by security scanners and make reverse engineering more difficult.