Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15FF31D31D445882F42A7A6C4627A6B9EB3D2E20BCA2703D467F443DE8FCFD05D9136A5 |
|
CONTENT
ssdeep
|
3072:d4o4aO+OxOVHxtxIxJxTx0xQxFxYxqxVxtxIxJxTxIxPxzxNxHx4x7xhxDxbxcxo:d4o43Yw2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ca4ab50ae9b534d6 |
|
VISUAL
aHash
|
fb0020200000ffff |
|
VISUAL
dHash
|
d3c1c5c3e1e14e0e |
|
VISUAL
wHash
|
ff3070302000ffff |
|
VISUAL
colorHash
|
07402040040 |
|
VISUAL
cropResistant
|
f2d3a1c5c1d3c3c3,e3000c4c0a000e06,9c272361e9e9c149,29c950d2fbf9fcfc,c3c3c3c3e3e1e1e3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 292 techniques to evade detection by security scanners and make reverse engineering more difficult.