Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14A23FCB0E0626E7F01C7A2D43A35478AE6C9C213CE23024A73FD975D5BE6D04DE57AA4 |
|
CONTENT
ssdeep
|
384:4qo43+xtUsBkGBPYrIIIVOAmMaplLlUsZ0zn5ySpgB+9gOeeebLeeecRIeee/USg:ibeIIIVYUsZSrTeeeHeeecSeeecV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f5c00f358d523d95 |
|
VISUAL
aHash
|
02e7ffffc3838001 |
|
VISUAL
dHash
|
86868e96160e0f2f |
|
VISUAL
wHash
|
02f3ffffd3830001 |
|
VISUAL
colorHash
|
08180000000 |
|
VISUAL
cropResistant
|
f0d0f0f0e0e0f0e0,e5d0cae0e26c3c9c,86868e96160e0f2f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 217 techniques to evade detection by security scanners and make reverse engineering more difficult.