Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B22331B26146597FD98B91C9BB74AB0DE1C7930BC6220D49F7F2834B9F82D60FC19621 |
|
CONTENT
ssdeep
|
768:ZoFZ8fnZ8fqFC37bGBKTtHZzAtbOWZ7viJBJBse+fZHzaDbcduhsty0gKIBKen8Y:s7PZFbj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
afa750503c7c6707 |
|
VISUAL
aHash
|
5effffff3f000000 |
|
VISUAL
dHash
|
b4dc473777cccc44 |
|
VISUAL
wHash
|
06ffffff3f000000 |
|
VISUAL
colorHash
|
1b006000080 |
|
VISUAL
cropResistant
|
f0d2cd4e734f3777,0b24d4e4e4944220,3ada596e373d1e9e,3cc2f33301c18f2f,3f75cec8ccca4440 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 132 techniques to evade detection by security scanners and make reverse engineering more difficult.