Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F7A3CF231249782B6037C6D16455AF3BD1B6CE5FFEA719005BEC97F62BEAC10B41B218 |
|
CONTENT
ssdeep
|
1536:YUy010ChjlItIxYTSICVnK3H9agvzEX3FQoqccuBi79EL+xk6c0jbsJuZ66moXE7:p10OlItHWlCslwxZH6N/V |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e242be8f4bba1ac2 |
|
VISUAL
aHash
|
ff00400000c2ffff |
|
VISUAL
dHash
|
51848dcccc860053 |
|
VISUAL
wHash
|
ff00000020ffffbf |
|
VISUAL
colorHash
|
020000001c0 |
|
VISUAL
cropResistant
|
0001c16561990092,af0f5d717d5dcbcb,a080c0a3a7c480a2,0400060e00755555,9e848c8cacccc830,008232caca328201 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 39 techniques to evade detection by security scanners and make reverse engineering more difficult.