Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T172632ABA52D8B26DC141D7D8E221BE3CB29E047DCE31C51E96EA8DD295C18AC40BD5CF |
|
CONTENT
ssdeep
|
768:85B4iF42zqW4gusfBY7ak3B7WaeMPpleZLJ7BFztQTHO4gGnaUrNE/FV3vlh7y76:85BU8uTBpO9tRvlVyF5xaYg |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
97b76c6cb4424b49 |
|
VISUAL
aHash
|
070f6e0f0f002020 |
|
VISUAL
dHash
|
9ceccccc3cd2d0c4 |
|
VISUAL
wHash
|
473f6f2f0f00383c |
|
VISUAL
colorHash
|
30600010000 |
|
VISUAL
cropResistant
|
f0c3e253b4dcfc68,9c9ce1d3c2c038b9,f9c4c2c2c6eeffde,9ceccccc3cd2d0c4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.