Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16703A596214856E5C1F38FD8941026947286EB5FC9718370C2BC4E3E2BD26A5B788F7F |
|
CONTENT
ssdeep
|
384:TJOfyezvez99Sez99NFKyXjJslwfififgRX3qdBI9j4XJSvOoDpybO0vsFijYK/b:JzNHJ+1a7kOo0hs4jY7yUjJoHXLQ4p |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c647d0b938be8e31 |
|
VISUAL
aHash
|
0030300000ffffff |
|
VISUAL
dHash
|
c4c4e4e41e270d69 |
|
VISUAL
wHash
|
7070300000ffffff |
|
VISUAL
colorHash
|
332010001c0 |
|
VISUAL
cropResistant
|
04040c0c0c200404,4e4e5a5a67e0f6f8,661817154d293120,e4c4c4e4e4649866 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 6 techniques to evade detection by security scanners and make reverse engineering more difficult.