Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B43297F1815168371673C5D8EAF6A719F2C28E98CA571691C2F8D32E1AC5EF1FD42228 |
|
CONTENT
ssdeep
|
192:AalY77+Ly9Tb/vYux4U32BNRAxPUa8cPUbi36rEJ55cBvhuo:i/wTo8Lbi36IJ55W5 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d7577d682a2a2a8a |
|
VISUAL
aHash
|
003effffffffffff |
|
VISUAL
dHash
|
1468696969000000 |
|
VISUAL
wHash
|
003c3d3d3c68f0f0 |
|
VISUAL
colorHash
|
070020100c0 |
|
VISUAL
cropResistant
|
0100140505010200,6c68696968020000,0000409090400000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 317 techniques to evade detection by security scanners and make reverse engineering more difficult.