Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12E246873421974274533C3D520BA5B3AE2969E4FFAA30A050FECD7FA1BE9CA0751B119 |
|
CONTENT
ssdeep
|
1536:PlfjiEYLOxwOJUHWJzvhdPNtz2V9ENLiLoQLLUf1ALT1TtLR1LCk8v2IYYRca60F:QSvr8DnIsFO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b698ca99c2ada569 |
|
VISUAL
aHash
|
fffc0707060700f0 |
|
VISUAL
dHash
|
804c4e6c2e3e4cc5 |
|
VISUAL
wHash
|
fffc0707070784f0 |
|
VISUAL
colorHash
|
03000000c00 |
|
VISUAL
cropResistant
|
804c4e6c2e3e4cc5,344cecae2ebcae6c,00002432b2300800,4140809090908068,4540809090909060 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1031 techniques to evade detection by security scanners and make reverse engineering more difficult.