Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AA33A471B204791D715780CAE273AA8E3180978FD7655FC1C6F5933AF4EACA2BD6128C |
|
CONTENT
ssdeep
|
384:R7PzF0+s3//fT3noIb6FExp9ST2qNwUHhIuM7Rww/QgNUM7C3zsE/cEcxT2NjaN+:4fcIeinpYUmBmC3zsscEcxTkaNcFd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8f681f602717705f |
|
VISUAL
aHash
|
0019797f74f73f3f |
|
VISUAL
dHash
|
f7b3b1e3e5846868 |
|
VISUAL
wHash
|
0011187f74773f3e |
|
VISUAL
colorHash
|
06007010000 |
|
VISUAL
cropResistant
|
f7b3b1e3e5846868,0000000101014141,0f41878696535a5a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 705 techniques to evade detection by security scanners and make reverse engineering more difficult.