Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F3C172B07195297F225389F2A4A1A73E60EDC64ED16BC184D6FDC2A927CEC80FC124E5 |
|
CONTENT
ssdeep
|
96:h1SYJHSYiNZui4m2nwPr6L+pjhpVMpKlGG8364LWYzPXTVYLgdt3MSzMmTHGoxNK:XSYqwVCpjhpVMpuN4COKLqtVklog |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cbc94963e34963e2 |
|
VISUAL
aHash
|
ffffffffff000000 |
|
VISUAL
dHash
|
f3322a324c4cd580 |
|
VISUAL
wHash
|
00ffffffff000000 |
|
VISUAL
colorHash
|
07000000e00 |
|
VISUAL
cropResistant
|
23322a2a32324d4c,000031cec6c620d0,4833c8ccd4420000,005544c0c5a09488 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 19 techniques to evade detection by security scanners and make reverse engineering more difficult.