Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BA8396B2B9636829215F12CF9117370D51C2D3CECA535AF862F443AC9AF5CA07BE71A4 |
|
CONTENT
ssdeep
|
768:JTs2ODhVBGvZW1pDnvFuFFytF0Xt1q5cKWu8UOYDRm:RsjDhVBGszDnwqEXt18cKn8UzDRm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ecc611994779936c |
|
VISUAL
aHash
|
fff3e1e1f3ffc300 |
|
VISUAL
dHash
|
d027272727121797 |
|
VISUAL
wHash
|
fef1c1e1a1ff8100 |
|
VISUAL
colorHash
|
0f001000180 |
|
VISUAL
cropResistant
|
d027272727121797,7bf6dcb0e0dcfc79,e0e0f0f0e0c0c0c0,54b26864fcf4e8f8,0000001000000041 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 520 techniques to evade detection by security scanners and make reverse engineering more difficult.