Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E6235B726332B8B843CB91DEF7382E46B2C6989DF8C74590B5C96A8D13C3C8161877B4 |
|
CONTENT
ssdeep
|
768:ac+EsZx8/G8QTRF4CDawuM5Bdow3M5BdLqN2/y9dGDUDF1E56ITmH+LXPnTyPqDZ:ac+EsZ/8Q9OCDawuM5Bqw3M5BEN2/y96 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
eee4917bc0943a93 |
|
VISUAL
aHash
|
fff393f3a100ffff |
|
VISUAL
dHash
|
274767674371c8c4 |
|
VISUAL
wHash
|
ffb181a1a1007e7e |
|
VISUAL
colorHash
|
06c01000000 |
|
VISUAL
cropResistant
|
274767674371c8c4,32004d0c6347574b,5e4f9f91b1d199db,cfe2cc8b87667a6a,15ac2d2b4b0e1d0d,8000b2808cb2968a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 18 techniques to evade detection by security scanners and make reverse engineering more difficult.