Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12992F8F760DC392A0A8753E7B736779AF028D10CE5C6958099FE8B6D61D8CE8EC17640 |
|
CONTENT
ssdeep
|
384:Gn34hWXxDk9dyrqNRDslmPy2Oxe9EDasdrN9eML43IHeYTMllXV+AwPFeZdq7Drv:i/XxDIwmPyjxe9jsHt4lYwllF+Py6Drv |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a89c7d72070f4769 |
|
VISUAL
aHash
|
00d3df3f7fc50100 |
|
VISUAL
dHash
|
37b7b7e9b5953537 |
|
VISUAL
wHash
|
00d7df3f7fc70100 |
|
VISUAL
colorHash
|
12c01000040 |
|
VISUAL
cropResistant
|
3fb49bd9ed783dfe,9cd190cc9c9c9c0c,519accca9b414172,37b7b7e9b5953537 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1139 techniques to evade detection by security scanners and make reverse engineering more difficult.