Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T183D2953D91211C2F859386DBF221774EE1A6CF4BE7170E9027F847EA2FC6C40E995299 |
|
CONTENT
ssdeep
|
384:YjDab0yRwKma0WoIIbBFGGkG4Pyv9+uIR4NyZ/GKVAuXGdLotWz0tPb4t+hazot+:oyXoII3Rk/NXGdLwHs+hB7C3+dIuIIu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ca11b16eb53ba43c |
|
VISUAL
aHash
|
f8f8f8f8f0f0f0ff |
|
VISUAL
dHash
|
c220202082a121b2 |
|
VISUAL
wHash
|
00f0f0f0f0f0f0ff |
|
VISUAL
colorHash
|
07201000c00 |
|
VISUAL
cropResistant
|
c220202082a121b2,c2e080a8d9f274b8,c5e5f3931a38e070,ccdc19189c92e365,0809084bc9daa7ce |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 44 techniques to evade detection by security scanners and make reverse engineering more difficult.