Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FCB33271A1213833522789CCB2714F9EB1D7931DCA534C86B3FC8BA99FEAD90E815E54 |
|
CONTENT
ssdeep
|
1536:BRfRejo7NDEGBSGoisQOklK7FWuUc0jPtzO9t47y1vlob2QMbTKUG3cVn7SuL0Q3:BBRA7wLAndY4+zbzoMx5zZcepTS6o |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a05dde48b51ced13 |
|
VISUAL
aHash
|
003e0003677175ff |
|
VISUAL
dHash
|
3168af9ecee3adce |
|
VISUAL
wHash
|
00ff0003677175ff |
|
VISUAL
colorHash
|
19201000180 |
|
VISUAL
cropResistant
|
0000122222220200,31218de3f16c6ef7,26252539392959b2,d2f0b0fefbffbbba,8080222200202380,3168af9ecee3adce |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 88 techniques to evade detection by security scanners and make reverse engineering more difficult.