Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T119F142A1D410DE3B0357C5E5A7B5BB0F7792C349CB07194063F882AAABD6CA0CF22598 |
|
CONTENT
ssdeep
|
96:TksBAnBOkXHeXU49YsZtWRSSDt7JuVFeaXSHFT6Xwz/78AxtmMTYMcoJ:QsBAngkXHeXUONtWrruO1zRYMMMb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9292ec8b8ced998e |
|
VISUAL
aHash
|
ff6e6e0e2e2e0000 |
|
VISUAL
dHash
|
ccccdcdcdcd8230c |
|
VISUAL
wHash
|
ffef6e2e2e2e0000 |
|
VISUAL
colorHash
|
03200008006 |
|
VISUAL
cropResistant
|
02cc8ccc8cdcdcdc,b6b6b836b336b2d6,139b366c7870f3f2,ccccdcccdcd82358 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 59 techniques to evade detection by security scanners and make reverse engineering more difficult.