Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16E7297713009A57F1833B738EBE2748D51219787D32585B041F213696BD2F7A88BB8AB |
|
CONTENT
ssdeep
|
192:/UMsKdYlQbN8gQUN/oKqxhgKNAY43kn3aW9H1mTRXsYoag5hDHA6TJ1y:/RsKOlQB8HU9oKqfgKSwV9HoRXUrc6JA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bf3fc5c0d0183467 |
|
VISUAL
aHash
|
ffa18181e7e7ffff |
|
VISUAL
dHash
|
a05b1f394d8c0008 |
|
VISUAL
wHash
|
7e00010141e7ffff |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
a05b1f394d8c0008,81a0a6a2a2a680a1,74b4b2b69d8c9c36,0000000000000000,e869b2b6968c8eb2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 91 techniques to evade detection by security scanners and make reverse engineering more difficult.