Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1419274309C8ABA3B63A353D1C752932BF2D48254D1174A1AD6FD8B6E1BD7E40DF62306 |
|
CONTENT
ssdeep
|
192:lf5XzzJWwJo5qOCN8fknzu7JyPj8EREPOIMNQM7/wGzc:lf5XzFz/56d2VWGISBwGzc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e659596664313bcc |
|
VISUAL
aHash
|
00ffffe7e7e7ff00 |
|
VISUAL
dHash
|
84f0384c0d4dcc32 |
|
VISUAL
wHash
|
007f3c242424ff00 |
|
VISUAL
colorHash
|
00030000000 |
|
VISUAL
cropResistant
|
d0f04e0c2c4dccf0,8198fc74f0303b35,a689c8b6e68e9140,49d49692c316cc0f,4c32b24c30b2300c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 16 techniques to evade detection by security scanners and make reverse engineering more difficult.