Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17304B5B151D1283E33378EDC7479BF8AF1A3E00FC98601A09BB53585A9E6FF498156E4 |
|
CONTENT
ssdeep
|
1536:t6G+u51P3ZiVDMwmSk3gGF6jp5JbIx16DFTg+vLDB9UQVliVYpSoPOmUCmECgOhy:t+UiVDMZSw45JhDFMwDBv6QD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
96966b6c69299396 |
|
VISUAL
aHash
|
067e7e7e14140000 |
|
VISUAL
dHash
|
dcececd4b4f4f412 |
|
VISUAL
wHash
|
6e7e7e7e76141400 |
|
VISUAL
colorHash
|
38c00010000 |
|
VISUAL
cropResistant
|
3f76e6aeb6aeb595,9b33a5a9bb33335b,dcececd4b4f4f412 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 9 techniques to evade detection by security scanners and make reverse engineering more difficult.