Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T120938532D352240390A7D4C8F1664B4E7352875BC6134AB6A7F817BAFECECB52761398 |
|
CONTENT
ssdeep
|
1536:PBOf9UF9UB9UM9UD9Ue9UV671r36mePEXeR12KPUgOd61eOtpQjWEUeeQBSlkw64:BBgEgPUgOd6WjWGhV2k222I2222222b3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b00d3c7bd2c3c2cb |
|
VISUAL
aHash
|
8383ffc7c3c7c7c7 |
|
VISUAL
dHash
|
3626269b8b8f8f8f |
|
VISUAL
wHash
|
8383fbc1c1c1c7c7 |
|
VISUAL
colorHash
|
06200038000 |
|
VISUAL
cropResistant
|
3626269b8b8f8f8f,8880c8cc2463c7c5,6332cc6c86c371e1,3725273727292b33 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.