Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19182847059C56633119343D06BE3AB4BB7C082D6DF27CB5946F44BAABBCAC51CE22718 |
|
CONTENT
ssdeep
|
192:dtII6xCFpRhuQDCtbbsLDKhN1UyPN89xhz6/6IrC3TXkpETSTczPYYwnf0N0jpO:dtIIGC5huoCtbbqDwN17y9vzXkGTRteO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9c9c36363cb63c1a |
|
VISUAL
aHash
|
063c181818183c18 |
|
VISUAL
dHash
|
ecf0b2b233f0d4f0 |
|
VISUAL
wHash
|
1e7c18383c3c7e3c |
|
VISUAL
colorHash
|
30200018002 |
|
VISUAL
cropResistant
|
f2f05c95aeaab636,49e1c0f0e097d8e0,ecf0b2b233f0d4f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 9 techniques to evade detection by security scanners and make reverse engineering more difficult.