Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1615409B5930C756F204B8BC8EA727634E36F95BCB57A42A08E6FC7710587CD4EA1B850 |
|
CONTENT
ssdeep
|
1536:hyRlDIX5s7xi+8dv5/+PXi5S/L5UYN9/YB2i8eeSy8Air+8EsNn74ari25vBDxuA:hynxpx7ZwaedyI6yacSx+1QEjOU+k |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f15f47271c3c2c34 |
|
VISUAL
aHash
|
006cffdfe7e7e7ff |
|
VISUAL
dHash
|
ccc80b1b161f1f1e |
|
VISUAL
wHash
|
0020ffcfc3c3c3c7 |
|
VISUAL
colorHash
|
00000030040 |
|
VISUAL
cropResistant
|
c80c3b1f0f1f1f1c,d4dcd4d992c8c94b,0000000000000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63933 techniques to evade detection by security scanners and make reverse engineering more difficult.