Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10E63A632A65659039097D2C4F1619B1E22828789C7174FA173F857BE7ECACF5AE123CC |
|
CONTENT
ssdeep
|
1536:zQOUbJo+uu0IuERbuPut7YuXuouaRPozXoZ7Yf+mkR2GRleVO+eH99hGbzSGc+u7:oWoi2ZeTmFmkR2k8VleH99hG3SGPuBAG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d3246c3269cf3996 |
|
VISUAL
aHash
|
40727c7e4e6c7e78 |
|
VISUAL
dHash
|
86c4d8d8dcd8d8d0 |
|
VISUAL
wHash
|
40527e7e4c6c7c78 |
|
VISUAL
colorHash
|
06200038000 |
|
VISUAL
cropResistant
|
86c4d8d8dcd8d8d0,956969d5dcc41b94,64643b33b939331f,2bebc9f92d2d250d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.