Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18C4431F54358A29CAC0E4FECDF7F5C61932D55F7E2C052A4A518CB80C6A24E6DE5EAC0 |
|
CONTENT
ssdeep
|
1536:H+RKe3M4C/5OCC2o35h/MML1ryBfSkBcjHbMYDM1+rrrrkkmqMcWMB1KyzGDUzFW:EAYbMMpmBfhBa7MW5Z1ebF4CKbvy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a46e07b9eccd3033 |
|
VISUAL
aHash
|
0303030307070707 |
|
VISUAL
dHash
|
666766279696d6d6 |
|
VISUAL
wHash
|
17073797070f2f07 |
|
VISUAL
colorHash
|
0fc00010000 |
|
VISUAL
cropResistant
|
b89ab1b580a0a0a0,9e96b2b2f0c0cccc,c9c9c9eaeaeae267,b131a9988eeeece4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 248 techniques to evade detection by security scanners and make reverse engineering more difficult.