Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T180B35CE5E2C4FA1320E35052B1A75657F239040EF61949B0FA8CD7E9F2D58AE41B33A9 |
|
CONTENT
ssdeep
|
1536:ZhtQCtQIvae+oE8U/FU/g/3eSannnM+/CrCqGqomgAjmlzQ2N0msQw:ZhtQCtNae+oE8U/F9bowjmfVw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8e5217ede9356107 |
|
VISUAL
aHash
|
000000fff3f33f3f |
|
VISUAL
dHash
|
fcf8fc3b2727677b |
|
VISUAL
wHash
|
000000fff3f33f3f |
|
VISUAL
colorHash
|
16401010000 |
|
VISUAL
cropResistant
|
f86c392727276e7f,8286aa8ccc828a82,c6b47cf9f8ece838,ad3b3b39392d2529,b29296b2c8f4a6ae,084d989919797be8,17b8aacb418e8eb0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 26 techniques to evade detection by security scanners and make reverse engineering more difficult.