Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BC13DC329444D82742DB8AC45576732A62FA831ACA270686FEF4C7ED1BDFC5CDA37214 |
|
CONTENT
ssdeep
|
768:A9/CsIx/j/LlAtaYs/Sk2YBy/Z/gUf79F:DsIxrLTSGBG/v79F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bce3479e3134b443 |
|
VISUAL
aHash
|
00ffffffffff0000 |
|
VISUAL
dHash
|
6b2bc439182926c5 |
|
VISUAL
wHash
|
00fdff8fcf9f0000 |
|
VISUAL
colorHash
|
07000e00000 |
|
VISUAL
cropResistant
|
8080808000808000,2b0bc43838183820,0000000000000000,004030c8c8c02000,01412194d4218101,2018e1e6cec01501 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 81 techniques to evade detection by security scanners and make reverse engineering more difficult.