Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A58375309040983B0197E2E5B235AB67A2E5C349CF834A91E7F9C35E5FC6CA1EF13695 |
|
CONTENT
ssdeep
|
1536:VquV44UquV44SsIAdd8444o68LNubmtVewWbXyS1ncpjwIkw7Dwovw3ANbjdw4Q+:Zyy20LNumtVeFXyS1ncOA1JcHFJ8pXK6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b85bc64a3b2f3831 |
|
VISUAL
aHash
|
00ff838f8fcfffe7 |
|
VISUAL
dHash
|
49911e1b1a984d0c |
|
VISUAL
wHash
|
00ff818182c6ffe7 |
|
VISUAL
colorHash
|
06007000000 |
|
VISUAL
cropResistant
|
419a1f1a1a984d0c,c024291a1a2820c0,2898989858282c24 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 49 techniques to evade detection by security scanners and make reverse engineering more difficult.