Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18AC2E127B144862A8D8B48EDFAB8BE56694D9545F730C84258F482FFAE31D9CFC2035D |
|
CONTENT
ssdeep
|
768:qpKp7p+Z3BX+ZGCMvoRCRzvzKDHFx+SxxkoINgmMZQYu67EZyQ5DMCWBerRO9deL:Cil+eMv9gqzN36wPZUelOmOBN6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8389bc3636dc686 |
|
VISUAL
aHash
|
81878381ffffffff |
|
VISUAL
dHash
|
3b3b373f3b271b1a |
|
VISUAL
wHash
|
81818181cfcfcfcf |
|
VISUAL
colorHash
|
06608010000 |
|
VISUAL
cropResistant
|
3b3b373f3b271b1a,dfd8585c33585cd8,fcf1fdfcd7dbcabc |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 25 techniques to evade detection by security scanners and make reverse engineering more difficult.