Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13B233330A960982A41CF66C8A576471922F7D306DB0307EDFAB193F58BCED6DCA37158 |
|
CONTENT
ssdeep
|
384:uVES2JfsKssJO5xVZjqTSLaNzlBC5e08gCFCTYzUH36wcKnJgWO+58VgPN4g0yj6:oEvEsIx/jmJlUCg5hdfUf79F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8e2c51b7c162573 |
|
VISUAL
aHash
|
ffffc3818104bdf3 |
|
VISUAL
dHash
|
2c13973b39385126 |
|
VISUAL
wHash
|
80ffd3898004bdf3 |
|
VISUAL
colorHash
|
07006000080 |
|
VISUAL
cropResistant
|
2793b73b39395526,0020402020200000,193d3d115d567676,3d3f764e4e6b6373,8e1667072327aaa4,9fdf1d4d44765e1e,163634766723223b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 127 techniques to evade detection by security scanners and make reverse engineering more difficult.