Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T124A3BA234219352B4437C2C1346A6B3BE1A6999BFEE709005EDCC7F62BF9CA0742B55D |
|
CONTENT
ssdeep
|
768:Pv+UItpR4nXF6YjOpSpFlTC6rrWjppFyMDKTlPjnBDH:Pv0tpR4nXBKpSpFl26vupRDOjnBDH |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f21cede51332e862 |
|
VISUAL
aHash
|
8000000cfcf1f1fd |
|
VISUAL
dHash
|
1ab6257c0c030309 |
|
VISUAL
wHash
|
8212100cfef1f1ff |
|
VISUAL
colorHash
|
0a401010040 |
|
VISUAL
cropResistant
|
90d0596424c6d6d3,3030d818bc7878f8,4800806060e00080,8000806060800018,1800906060c000d0,0c0f03030d030901,9200a080a0a000e2,30e7c6f470f0e4ad,217119595cdc5b4b,2ab6a77c5c030309 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 111 techniques to evade detection by security scanners and make reverse engineering more difficult.