Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17033C831714CAA1701AE82E44297AF377295928ACB634789C3F8C7F84EDDDF07E62156 |
|
CONTENT
ssdeep
|
384:NBaIIURaMuR1Gr/6le1O6IYl7Sa6cWP6zeUTt2fWgfdJS3tJPZ+t/S+yLslQ6Cbw:N8IIURA4//1O6IYpSa6p3Ezs3OcQM8o |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0cecc9399ce319a |
|
VISUAL
aHash
|
ffc3c3e7c7c3e7c3 |
|
VISUAL
dHash
|
1e8e86168e8e0e96 |
|
VISUAL
wHash
|
87c3c3c3c3c3c3c3 |
|
VISUAL
colorHash
|
06200018001 |
|
VISUAL
cropResistant
|
1e8e86168e8e0e96,316a5a54556370e9,6de7d6940deccdad,697978282aaac696 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 37 techniques to evade detection by security scanners and make reverse engineering more difficult.