Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E7146494F2D29C32311F81F2A4A467090192FBBBC7411BC767B146B1EBF58BD784E299 |
|
CONTENT
ssdeep
|
3072:IRcSI4MX0szJ67TObMInVrgKAMOPXvxMhk+utOWzn17/jSeOC37VWBIr4c+r:IzsVWxWVQFcc+r |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a3500c7d77776708 |
|
VISUAL
aHash
|
007fe7e7e7e7ffff |
|
VISUAL
dHash
|
0cb28c4c4c4da2e4 |
|
VISUAL
wHash
|
0000e7e7e7e7073e |
|
VISUAL
colorHash
|
06206000000 |
|
VISUAL
cropResistant
|
8000c082a2800080,b08c4d4c4d4ca0ec,4145808280c02120,1931260938232f2f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 190 techniques to evade detection by security scanners and make reverse engineering more difficult.