Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1526251E1D090EC37535385D8B7B57B1B37A1C385CF46099413F853AAABDECA0CB2259A |
|
CONTENT
ssdeep
|
192:QO7p2kF5XckzYhhn3Zc/A8i5Dd5qKpCMFc+B5qO9nROFCzBXTNDlU8F:Q05XLGnpc415DnqKpPc+BnJ4uXTNDa8F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c34bb43c8bf284cb |
|
VISUAL
aHash
|
ff0028282800ffff |
|
VISUAL
dHash
|
ac4a4a4a4a960ee8 |
|
VISUAL
wHash
|
ff2028282880ffff |
|
VISUAL
colorHash
|
03000000007 |
|
VISUAL
cropResistant
|
000c0c2a2b0c0810,ce9692b393968ecc,76c6c2c0fcbc9899,60160e8e880cb0f0,a44a4a4a5a4a6284 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 55 techniques to evade detection by security scanners and make reverse engineering more difficult.