Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17A331F30A861DC3600DFB6C5A635472922F6C306C61307E9FAF597B94BDEC69DE23258 |
|
CONTENT
ssdeep
|
384:bhIbsJO5xVZjqTSRwz8eu0nuquPzz6eupnu+uRzAVeuRnuZuhE5TcJi6sbsjsssO:GbsIx/jJwi7fD6SWjMiAUf75sJBCh3mq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c74783382787167d |
|
VISUAL
aHash
|
2020202000feffff |
|
VISUAL
dHash
|
ccc2c8c82aa8000e |
|
VISUAL
wHash
|
2060606080ffffff |
|
VISUAL
colorHash
|
0fc01000000 |
|
VISUAL
cropResistant
|
3beccacaca4c090d,5a2838a8526bebc3,a91e324a541a9a1a,ac00100c0c120e00,ccc0c2c8c8c03aa8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 31 techniques to evade detection by security scanners and make reverse engineering more difficult.