Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1781221E1C044ED3A036355D9F7F56B9B77A1C384CF06094453F4826B9FDADA0CA12AA9 |
|
CONTENT
ssdeep
|
96:TkKWD7khOhHW0eG9V7Idt7DApE2wvlo3epXKHlCedXzHl21KX54/Jt7t//aS4bU7:Q7D7khOhHWs9udxApEzsPFc24xjlQa |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b633c96d2898ce66 |
|
VISUAL
aHash
|
0124240602e7ffff |
|
VISUAL
dHash
|
ed4c6ccdcc4e2830 |
|
VISUAL
wHash
|
0104240606ffffff |
|
VISUAL
colorHash
|
07000000006 |
|
VISUAL
cropResistant
|
ed4c6ccdcc4e2830,205a5b00a4042418,75ebd4d45555d555,9484e494959468e6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 58 techniques to evade detection by security scanners and make reverse engineering more difficult.