Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1340273E0D464ED37076285D5A7F27B2B32A5C349CF020E5053F493AA67CECA1CB2199D |
|
CONTENT
ssdeep
|
96:TkmXxOWEMOEMOnzHORPnSTxPjSYLmkHl7sxcXYHluWXWHl6qX6HluWXiHlTSXc7V:QmAWEZEZnzHO8l7Lmk08sYd7nG8F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b17d09e680f983ec |
|
VISUAL
aHash
|
ff00cfcff726ff7f |
|
VISUAL
dHash
|
12301e1ac5cd00c4 |
|
VISUAL
wHash
|
ff0003877100ff3f |
|
VISUAL
colorHash
|
07002000180 |
|
VISUAL
cropResistant
|
0000000000000000,b05c1a26cd5804d0,538e5a5212929212 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.