Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T124F2CC21A844ED2700DFA9D8A6B7562A61FA8345C51316C9FEB5C3FA17EFC6DCA33140 |
|
CONTENT
ssdeep
|
768:lx1sIx/jmUO2Ukf2Z8i2huU2etbPUJMRtx1A1Uf7x:psIxqUoyRtx6S7x |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec00fb1243ee7953 |
|
VISUAL
aHash
|
00d3d35300dbf3fb |
|
VISUAL
dHash
|
9993b7a7d22b2713 |
|
VISUAL
wHash
|
00d3d35300dfe3f3 |
|
VISUAL
colorHash
|
06206000000 |
|
VISUAL
cropResistant
|
b3339397b727a7a7,1b2b232f07331313,cccc33cc489793b3,7747c54349494949,1397b7a727a7c3d8,3d1c183c393b796d,e4d69abb3abae0e8,9b6969616868666e,69243435918a8925 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 50 techniques to evade detection by security scanners and make reverse engineering more difficult.