Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T144235AB26332B4B843DB91EEE7382D56B2D2989DF8C74554F1C95A8D13C3C812297BB4 |
|
CONTENT
ssdeep
|
768:ab+EsZx8/G8QcXude4zDawBM5BTw2M5BYqN2/y9dGDUDF1E56ITmH+LXPnTyPqDZ:ab+EsZ/8QcXEJzDawBM5BTw2M5BpN2/V |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9550ea3ad584b3cd |
|
VISUAL
aHash
|
0000060e060fffff |
|
VISUAL
dHash
|
0c8caeac8e3cec05 |
|
VISUAL
wHash
|
04000e0f0f0fffff |
|
VISUAL
colorHash
|
030000001c0 |
|
VISUAL
cropResistant
|
00000c0c00080c08,aeacac1c3cec0435,9b7b6792a499a4a5,1014da5328ea642c,2c8c8eacac8e1cec |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 19 techniques to evade detection by security scanners and make reverse engineering more difficult.