Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T112738732E3830807A0AFD1D5B0225B5D12958648C7570BB9767E36B6FACFDF52623398 |
|
CONTENT
ssdeep
|
1536:6l/teh3SmlSNK8P4jlcIGo3HI0Wc1WiUVpHx4hc8d1zdbeidwNcrMNDLWR52h7iY:9Cm8NK8IGOHsJiepR4GmdpdkcmDiqdig |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c56d2c9196e9ac4d |
|
VISUAL
aHash
|
c30052ff2cffff14 |
|
VISUAL
dHash
|
8a86a6d8d0d8d8a4 |
|
VISUAL
wHash
|
c30052ff287eff10 |
|
VISUAL
colorHash
|
06000038000 |
|
VISUAL
cropResistant
|
8a86a6d8d0d8d8a4,a8a2c5ee3641c2c5,0000000000000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.