Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T152B32B33D18017FB0F4386D4AE69777EC352854ACB13859AC0A9425DA7CEDE5D8A32CE |
|
CONTENT
ssdeep
|
3072:zyKA9xawLYlRTpb3Zxro3lhrF+ClrmxxxSa0E6ga:zyKA9xawslRTpb3ZVV0E6h |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d8a976adc8a5c899 |
|
VISUAL
aHash
|
0000181c1c180000 |
|
VISUAL
dHash
|
300c323232320c38 |
|
VISUAL
wHash
|
ff879b9b98980404 |
|
VISUAL
colorHash
|
070010081c0 |
|
VISUAL
cropResistant
|
b6a68a9696c6b8ba,300c323232320c38 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 19333 techniques to evade detection by security scanners and make reverse engineering more difficult.