Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B7C3CDE188A4753A40FAB1D5A5ADFB26B2E14106CE41466243FDC36CD7DAF80FDB3A14 |
|
CONTENT
ssdeep
|
768:WzBgdR+WKIIecIIeXP2FSrSTWZxE0ToYg1dR+5tBEG:WXBIIecIIeXPxOWDkYgQ7BL |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b11bcf3331191357 |
|
VISUAL
aHash
|
00ffffc3c3c3ffef |
|
VISUAL
dHash
|
980696969696160e |
|
VISUAL
wHash
|
00c7c3c3c3c3c7e7 |
|
VISUAL
colorHash
|
06000000180 |
|
VISUAL
cropResistant
|
828082c0d0c28282,9e069696969e160f,4798989898989827,f7ed8d4d454a4bcf,33252d3a791b2b2b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1079 techniques to evade detection by security scanners and make reverse engineering more difficult.