Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T150D43BA4F2E06819439342B6A17F364573B6141EA62544187BB9C8E9B9E4C4D323FFFC |
|
CONTENT
ssdeep
|
6144:K16l+KKVMqxRPyUDP0SutX/KHphBXi+ZcWW3GjwHmN8wXKB3q7lBMq5LtlJs8vlK:K16l+KKVM7OcNCK0Bn5GMA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8e794ba6b04e698e |
|
VISUAL
aHash
|
00003f073f003000 |
|
VISUAL
dHash
|
054a693c6c666a69 |
|
VISUAL
wHash
|
80a0bf8fbfa0bf20 |
|
VISUAL
colorHash
|
38402008000 |
|
VISUAL
cropResistant
|
caca0a4359f9e4dc,d8f0f0b878bc6d6c,054a693c6c666a69 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 441 techniques to evade detection by security scanners and make reverse engineering more difficult.