Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1842386B3445AE53B42A6C1DC8214FB5EE3D28149CFA7DA4163F4839D9FC2E9089B3949 |
|
CONTENT
ssdeep
|
384:uVmxbDc7GZi2it0it9GFKeC3dbGf9Q+TqLaB89zphblOWb0tar30uu1TyYTuXu2U:uoxM7Gm5Gfi+evFdY1D1NTu+2SZ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9110eaac6dede992 |
|
VISUAL
aHash
|
f904040004ffffff |
|
VISUAL
dHash
|
33ccc8aa889b230b |
|
VISUAL
wHash
|
fb04000000ffffff |
|
VISUAL
colorHash
|
0e400030000 |
|
VISUAL
cropResistant
|
03232323232323c3,d8c88aa89a232b0b,2b6a9aa2e26a6b2b,fac8ccc8daa8ac9a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1219 techniques to evade detection by security scanners and make reverse engineering more difficult.