Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T165A40DB1120424EE1BE3FDD464A2FA8760B2C9E5E21B4DCE65AC5A4D5FC1FE0C8D4399 |
|
CONTENT
ssdeep
|
3072:0pYoUkeus7EMA1n9lEMA1n9lEMA1n9lEMA1n9lEMA1n9lEMA1n9s:7Gs7E1E1E1E1E1Ec |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
edb69260e948e996 |
|
VISUAL
aHash
|
fffffbf1f10000ff |
|
VISUAL
dHash
|
2b2c233323939c22 |
|
VISUAL
wHash
|
fba7a1d1f10000ff |
|
VISUAL
colorHash
|
0e006010000 |
|
VISUAL
cropResistant
|
2b2f2d2313232393,0004306169691420,20003032002b5353,e8ecf0f0e8a2b079,80909000dcf8f000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 281 techniques to evade detection by security scanners and make reverse engineering more difficult.