Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T110E3A6B37A626836225F41CF91172F4DA1C1D3C9D94266E5B2F4836C8BF1D91FBA224C |
|
CONTENT
ssdeep
|
1536:IJKSVVEVw1t57pcOcLGk0cOc9GTLcOcnGgLcOcRGQlW0ypr3QiOiN7za9GNjLEnw:IVzVQmuAZ2i5s2c |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
eb0f94909ec8ea2e |
|
VISUAL
aHash
|
ff00818181c1ffff |
|
VISUAL
dHash
|
680b3333331b8d6c |
|
VISUAL
wHash
|
ff0081818181ffff |
|
VISUAL
colorHash
|
160000001c0 |
|
VISUAL
cropResistant
|
6a696992614b4080,333333331b934c07,82868a8e347879d9,0000000000000000,8cd2f2f090b4b4c0,6090939094969160,6090939894939060,6090919690919060 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1047 techniques to evade detection by security scanners and make reverse engineering more difficult.