Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1310487B2D3400B6B71E74BE4B065B72F619B8999E1878598F6F40395BBCFCA018813DD |
|
CONTENT
ssdeep
|
768:JKD0ZN0jf35bM5S73vA4N7d3fYhS1tfh98JzA1/pgby2QD91GUjTByFAZBDkPvL7:JKgNo31MSrAsPZ6QPMuq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9ccc63c21d1fc91b |
|
VISUAL
aHash
|
ffff18181c180000 |
|
VISUAL
dHash
|
ccb63332b2b23c5c |
|
VISUAL
wHash
|
ffff191e1e3e0000 |
|
VISUAL
colorHash
|
13000000007 |
|
VISUAL
cropResistant
|
8ea6aaaaaabeba29,ccb63332b2b23c5c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5697 techniques to evade detection by security scanners and make reverse engineering more difficult.