Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EBF21021A951DC2341DF99C9A5761B2A62F9434AC6030A98FAF8D3F557EFCBCE633005 |
|
CONTENT
ssdeep
|
768:ELZx6RA8sIx/jBKgKlk61BkCe0lp8tNZiyfWLLmGCcQ6smRk71Uf7x:tRA8sIxO1+TwLLmUP6G7x |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3a79c41c718a677 |
|
VISUAL
aHash
|
ffffffff20000090 |
|
VISUAL
dHash
|
e4f208c9ccc0b031 |
|
VISUAL
wHash
|
ffffffff00000000 |
|
VISUAL
colorHash
|
0b0020001c0 |
|
VISUAL
cropResistant
|
0000000010480c08,f2000f0e08d1cccc,97b2ec2434aabccd,6222002000000000,9aece4f07232f2f0,c0cc4cc3b9b03031 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 28 techniques to evade detection by security scanners and make reverse engineering more difficult.