Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CFE1E7E75224872E5592E17CEF63F0D0938AA09FE6A6C9D0E79ECB6910D7CD0F653810 |
|
CONTENT
ssdeep
|
96:TGPS6i6SzEIDKcGAng2+3wehaBQ8VjKx3NuZkTmB0qMcSPWSic/Coa:aPS6i6StGejywAcQSyUZxBcFL/W |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bcc343364d36516b |
|
VISUAL
aHash
|
40ffff9f838383db |
|
VISUAL
dHash
|
ce281c2b2b1f0f3a |
|
VISUAL
wHash
|
00ffdf9b838383c2 |
|
VISUAL
colorHash
|
06e00000000 |
|
VISUAL
cropResistant
|
ce281c3b2b1f0f2a,719c948cb8969ef0,00020616060281a3,0103138b92030001,0000000000000000,ede6e6ccccdecccc,1202322a2e2e0f00 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.