Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T177F3A671BB521436357F42DF90072B4C60D3E39EC60649E4B3F80269E7F1DA47AA62E9 |
|
CONTENT
ssdeep
|
1536:XUJIAgzS7gTIeawX6QjpfzSVnkISt1FWXa1fStG7St1eStZrStMu7V3dA5bSD77d:E2FAa0u7V3dA5bSD77rfFeMhGnj0IoD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c64ef931f131c88e |
|
VISUAL
aHash
|
00303064360607ff |
|
VISUAL
dHash
|
9464e4cce4eedeac |
|
VISUAL
wHash
|
00303076377f07ff |
|
VISUAL
colorHash
|
19080002080 |
|
VISUAL
cropResistant
|
40000000126d9233,3bb24c3200000000,dc00080000000000,946464ccece6dede,002c9469a9a4a2a4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 141 techniques to evade detection by security scanners and make reverse engineering more difficult.