Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15D435B72A2367D7D42DF91DEF73C2A52B2C39949E5C685A0B5C8928E13C3CC161877B8 |
|
CONTENT
ssdeep
|
1536:aKs+EsZ/8vRIIvDTw9M5BkwgM5BAY+M5BaN2/y9dGoDF1sPnTA4IE3wtwH:a4lIHwfwEYgN2aD3Hsqa |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bd2dc23cf0c2c8cb |
|
VISUAL
aHash
|
938383838383ffff |
|
VISUAL
dHash
|
2626262626266476 |
|
VISUAL
wHash
|
8383838383833fff |
|
VISUAL
colorHash
|
07000000038 |
|
VISUAL
cropResistant
|
2626262626266476,a64552722b6a6d6a,b2d6d9e916600000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 54 techniques to evade detection by security scanners and make reverse engineering more difficult.