Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16A74B431D2F34277457E3694F121BBCAA6D3D74BC3C2ABFA466881942B84C8A5D135EC |
|
CONTENT
ssdeep
|
3072:AVIHnzxdgB59wEB3fH2dXYFdNPDodbPd+:AYgB59wEB3U+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bf3dc09295c1366a |
|
VISUAL
aHash
|
ffc181838181fdff |
|
VISUAL
dHash
|
40131b37372b4b03 |
|
VISUAL
wHash
|
ff8181838181f9fd |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
40131b37372b4b03,a28081f81ad880a0,86278f8c2833e6cf,99ad7b7b7b6cffa6,292c1e1b4b6c6e43 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1204 techniques to evade detection by security scanners and make reverse engineering more difficult.