Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T122B2C4326A44BE3A50C7C6E09722676733AAE3E6CA47131503F8C37D8FC6E95DD66250 |
|
CONTENT
ssdeep
|
384:7u44oqDdcf/iveNAHvgS/UbELTpgm2l9wJlskz1LEnxZzFRMlXn:a44r6f/iveNAHvgS/aEfpgmEc1LM1MNn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9232ed69a9be2ca2 |
|
VISUAL
aHash
|
000404040400ffff |
|
VISUAL
dHash
|
53cdcdcdcd323c30 |
|
VISUAL
wHash
|
012467076700ffff |
|
VISUAL
colorHash
|
02000000007 |
|
VISUAL
cropResistant
|
aaae92b8b082bac0,a280801717808092,0000683034383002,33cdcdcdedcdcf70 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 42 techniques to evade detection by security scanners and make reverse engineering more difficult.