Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B084BC70929A653B4477C2D830F9573962DAD28DD9630C074FFCA7F50BEDCA6B44A04A |
|
CONTENT
ssdeep
|
1536:6GKPBBb0ZxSGtXUI356XCLPGRfTk9ypaUUNrZDq8PKi7MP7lYvK30XOn543S9DlJ:+pz+5ajqz+5z/+58+5Fqz+5kP |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c9d5b022c52fcc4f |
|
VISUAL
aHash
|
ffc0f878787901ff |
|
VISUAL
dHash
|
941073d2f1d153a4 |
|
VISUAL
wHash
|
ff80f838383101ff |
|
VISUAL
colorHash
|
02001000180 |
|
VISUAL
cropResistant
|
cc94941833737272,8282828282828282,cb172e5d3264dba4,a0a0a0a0aaa4a727,943172f2d1f1575b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 322 techniques to evade detection by security scanners and make reverse engineering more difficult.