Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13192D9F1E2E464FA9107CBD0D8317B16B1E760BDEB454798D1F487ECA792DD0A848C94 |
|
CONTENT
ssdeep
|
384:0O3LrbJ6dsjNOcKSRQSkuf9u9+9M9/D2UpZkRBpgKWtJFmUCn8ODJFmgyYefCWGZ:pcdkNOceSk6goG4UDkRBpg2/AI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ddd9a626a0a2a2b7 |
|
VISUAL
aHash
|
fff8fcbc80800000 |
|
VISUAL
dHash
|
0030303020010000 |
|
VISUAL
wHash
|
fffcfcfcc0c0c000 |
|
VISUAL
colorHash
|
11000000038 |
|
VISUAL
cropResistant
|
3004303030303020,b288aa232b3323e2,3030303000010000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.