Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EB334A736762B8BC83DB81DDB7392E45B2C5A49DE8870450B1D86AED23D3C8271877B4 |
|
CONTENT
ssdeep
|
1536:a5BPv+EsZ/8peAODDTEe+wKMJBtwAFMJBDwZUXx+y9dQyDF1ZAU84HaXwI:a5BPAJ+wPwDUUXxpDzHy7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
aa3dd4d0b5c035d5 |
|
VISUAL
aHash
|
0701010101017d03 |
|
VISUAL
dHash
|
7b737bdb5bcbcbfb |
|
VISUAL
wHash
|
ff010105013f7f3f |
|
VISUAL
colorHash
|
010030000c0 |
|
VISUAL
cropResistant
|
7b737bdb5bcbcbfb,01c0c402a0a0c9c0,01d0d401aaa0b000,03ec6c0109a09012,fef9ffccfed4d4dc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 18 techniques to evade detection by security scanners and make reverse engineering more difficult.