Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E1631E30D515DC27019795C9A232576A62F58345C6130B98FAF983FA6FCFCA8DE33298 |
|
CONTENT
ssdeep
|
768:ZachZtsIx/jG2dHBIr7Gd9DTWP4iPODQoEqp1ZRCUf79F:ZamtsIxi2dHwGdRTWP4iPODDdp/79F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c67fd908242b4bd6 |
|
VISUAL
aHash
|
00feb6a31200ffff |
|
VISUAL
dHash
|
d3646c6ee4e51382 |
|
VISUAL
wHash
|
00ffa6a20200ffff |
|
VISUAL
colorHash
|
06006000000 |
|
VISUAL
cropResistant
|
0000000000000000,0000469612600202,000080a0a080a0a0,c4646c6c6ea4e4e5,7ed0d2d0bcb4f478,00aa555544555500,0000020102020200,5252122cd8d88200,646c6c66a6e4e5e1,1343034b9e193597 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 86 techniques to evade detection by security scanners and make reverse engineering more difficult.