Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CCA33BB03658F5B716F343A720DB6202F2794A2FD40F8C60B354EC9A639DC9A5167F86 |
|
CONTENT
ssdeep
|
1536:wXbaG7Jp6iI4z+M1gTVq53QSoHxh8N6FmbXhjaPnQsR+Fuopc:AJI4z+nTjzmN6UbtZ9S |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e54d9a9879a1989e |
|
VISUAL
aHash
|
c000000000ffffff |
|
VISUAL
dHash
|
23c6434302300c0c |
|
VISUAL
wHash
|
ff00000000ffffff |
|
VISUAL
colorHash
|
030020001c0 |
|
VISUAL
cropResistant
|
002b2b2b2b6b0000,74393539625230ba,59a3b49052565233,c080b0baa680c0c0,02000000600c0e00,0006e34343c30200 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.