Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11F93B8B0A1D132B38207ABC86135576A77A761BEDBE3460483BC8F99D7CBC95CD8584C |
|
CONTENT
ssdeep
|
1536:ROUmU3UMUrUNUtUefUAU+fhHzloo40adJ1C+WVuvySV4gDGvR9wTldr+5/RKigyp:ReXZZPVwfL2U/ScqvWvCN41o/N |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9d8d9e6666626361 |
|
VISUAL
aHash
|
1fff3f1800000000 |
|
VISUAL
dHash
|
6d72db34320b2d2d |
|
VISUAL
wHash
|
3fffffff00008080 |
|
VISUAL
colorHash
|
32002010000 |
|
VISUAL
cropResistant
|
d6667651968acb92,ce8e161726262323,d8c6468b8b194b4c,d2c6363c323a1e1e,6d72db34320b2d2d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 189502 techniques to evade detection by security scanners and make reverse engineering more difficult.