Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T147740033021835264137C7D430A99B37D2A69D5FFAA70A414FECD7E72BEDCA0B45A11A |
|
CONTENT
ssdeep
|
1536:EbtsU8PjpMq1Wiz32jx+Qvt8sPB3IxknNkCR7VYWs/iQqKvF/BlqgFwe95MGIoV2:4QGLfFiU+RltFwe95TV3lliydo |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bcbc43c71e43b318 |
|
VISUAL
aHash
|
ffffffffffff0000 |
|
VISUAL
dHash
|
2b373e3a3600f030 |
|
VISUAL
wHash
|
ff83838f8fff0000 |
|
VISUAL
colorHash
|
0e180000000 |
|
VISUAL
cropResistant
|
2b27363e3a3e2680,a2b2007070002018 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 41 techniques to evade detection by security scanners and make reverse engineering more difficult.