Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11F425133B500CC2A8D9B86CCF2C49989516DC345FB3248C661B491BF7BC5CF06AA97AD |
|
CONTENT
ssdeep
|
192:tlSdfHzghUhIWSgUWcx+jix1McnthWeNWbnbfMmUU8VCogu5CuFud:tAfHzghU+WSDCvfMmUFCogu5CuFud |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8fb0303e94cc8f4f |
|
VISUAL
aHash
|
13333b3b39393939 |
|
VISUAL
dHash
|
b7d3e3f363636363 |
|
VISUAL
wHash
|
1b13393b39393939 |
|
VISUAL
colorHash
|
0e283000000 |
|
VISUAL
cropResistant
|
783b339bd99b9317,9afadadada5a1a19,e0ec6c6c6c6c68ec,e0c4e0c0c0e0e246,bbe969e969696169 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.