Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E695BC30B7911006F7B6E3C4F5A2CBD833434BA2D94149BEA6D48B37F49C116B4E5A6E |
|
CONTENT
ssdeep
|
3072:beEofvMJOaE6RFdtdfSz7WJrG/AhcMwf6joG/akBIbyvAaTDHpO/rWf4Eb/+bLfe:1oHUOO3SUBvhCG8LGPEQPEw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f59a319a8a758ac6 |
|
VISUAL
aHash
|
c7c3c3c3ffc7c3c3 |
|
VISUAL
dHash
|
9e8e8e968e8e968e |
|
VISUAL
wHash
|
c3c3c3c3c7c3c2c3 |
|
VISUAL
colorHash
|
06600000400 |
|
VISUAL
cropResistant
|
9e8e8e968e8e968e,16969797969797b6,d9cbe9c9c9f499d9,9edc949496921396,91c9a452526baba5 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 204 techniques to evade detection by security scanners and make reverse engineering more difficult.