Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19D72FEB256405C3F2B97ED55D9A27A0A51B3D1EBD01E18C5B3EC7E8E0FC5EA0C8C2A51 |
|
CONTENT
ssdeep
|
192:/Wn+LJF/8EZTgwwmrQ6byOAr62fBYy3ZyPmy0DZY4FTT1baeybkrRiera4IfbevC:+n+HLVgn6b9Ar6ckX8QEge/+i2R3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b127470e388ec7b9 |
|
VISUAL
aHash
|
0000ffdfdfffffff |
|
VISUAL
dHash
|
6098009490001019 |
|
VISUAL
wHash
|
00000303cfffffcc |
|
VISUAL
colorHash
|
07600000006 |
|
VISUAL
cropResistant
|
4000606860600040,181e169400000019,008030c8c0a42010 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10376 techniques to evade detection by security scanners and make reverse engineering more difficult.