Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CA93B732A044A93A41CB4BC4E7316658A3B68345E66201CCFFFEC3A6569FCFAC937554 |
|
CONTENT
ssdeep
|
1536:UMsDZKaF75SCUC8L82hEiTbYG5X5eEqNXevisIxS:UMsDZ759b8L82hzYaeEniW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
fa50848f29d1e8be |
|
VISUAL
aHash
|
ff00c00001fffff7 |
|
VISUAL
dHash
|
d227219b1b232c2b |
|
VISUAL
wHash
|
ff00800000fffff7 |
|
VISUAL
colorHash
|
0f380000000 |
|
VISUAL
cropResistant
|
411333311093030c,c9ce8699c4c79319,a1b5d91dbd9db7b6,7dad9b7323cada9a,b31b032b01132f2b,44272d31b35b132b,1759cce494cc6b0f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 42 techniques to evade detection by security scanners and make reverse engineering more difficult.