Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AFF21A00A120AA16405796A9D7BEFE8563FE90C6F54209E456FF871DB9FBCC4F83A610 |
|
CONTENT
ssdeep
|
384:Wrqfe47jBOILuJ1bP7vMgKu/zuou8MLpjy6S3fY7sNAw51RchPYNBTq+uQtSj7OK:FVSKYtSSTGT+RxyrFa+v3T |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b06c9a93cd6d309e |
|
VISUAL
aHash
|
ffffc3c3c3c3ffff |
|
VISUAL
dHash
|
94969696969e968c |
|
VISUAL
wHash
|
e700000000000ce7 |
|
VISUAL
colorHash
|
06001000180 |
|
VISUAL
cropResistant
|
94969696969e968c,e9cc963696ce8ee8,f073b0b2b0969632 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 1079 techniques to evade detection by security scanners and make reverse engineering more difficult.