Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18D33A4B349C4663B054382C6A5A1BF49F2D5401ACBB10BD879FCCA8DC7A2E63DD365C9 |
|
CONTENT
ssdeep
|
768:7bx+xd7DMTMdiune8qZUQZol4F/+OX9fJVFPGqTbNgUp6sLDtX2JXR+GopKQ4Jd7:7bx+xd7eQAf+vOq/kJsO7pCf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
946b6d58b6c36d18 |
|
VISUAL
aHash
|
001000763e183c06 |
|
VISUAL
dHash
|
32e4c3ccdcb3d134 |
|
VISUAL
wHash
|
18107e7e1e7e7c06 |
|
VISUAL
colorHash
|
07001008240 |
|
VISUAL
cropResistant
|
808088e73153538c,a01e362b2b272c50,32e4c3ccdcb3d134 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 986 techniques to evade detection by security scanners and make reverse engineering more difficult.