Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T126F2D7720244693E1963D3D9B6847FBCD6D5DA4FDF8285C9B3F8814E7782E529E022C2 |
|
CONTENT
ssdeep
|
768:Lsq+Y+5ouC8JIWjaI3j/ZjjFjwpYj/6j05OjfIvDj85Ejxcjwf+:N3UZupYf5WqU5CP+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bf483887b6c08c3f |
|
VISUAL
aHash
|
ff8181ff87a7ff87 |
|
VISUAL
dHash
|
6333334d6c6f5b2d |
|
VISUAL
wHash
|
b18181ff87878f07 |
|
VISUAL
colorHash
|
07000030000 |
|
VISUAL
cropResistant
|
6333334d6c6f5b2d,6d2e27394f6f5ede,33373179797159d9,6575ea6a1a3fad3c,aca4a48bcf677148,533a7adbd1333938 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 36 techniques to evade detection by security scanners and make reverse engineering more difficult.