Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13774FC3E3300E63F3263825AA455A295E38FBD1AD85F4855D3BCDA87AB99CD1C173E40 |
|
CONTENT
ssdeep
|
3072:kIA0G+q1ln87IDoqqsb1gc4+xWVaYh0aYHmaYQaYjcYaYKkaYTaYGqm2tDmGOv/0:k+KtCv/lUjFRz6A0Kt7ORFxJy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e061ad61e169bde1 |
|
VISUAL
aHash
|
e300006040001fff |
|
VISUAL
dHash
|
8f3d1181891d7b04 |
|
VISUAL
wHash
|
e70101e0e101ffff |
|
VISUAL
colorHash
|
31038000000 |
|
VISUAL
cropResistant
|
8f3d1181891d7b04,80008855516800c0,8f3c1c418198387b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 90 techniques to evade detection by security scanners and make reverse engineering more difficult.