Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FF03523A61448A3F22D7C2D677B46A1FE2E6D24ACA971A46A3F8C30D07D7DC4DD31492 |
|
CONTENT
ssdeep
|
384:9EHy+mVQf/MSQHO+ISSKPhcx+HkaSQan2JBXke6AKI2+Sl/7qiq:9EHy+m+H+IA4WaDe6fI2+S0iq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c763b85cc303bcb1 |
|
VISUAL
aHash
|
fd002060f09000ff |
|
VISUAL
dHash
|
41824ac8e020b04b |
|
VISUAL
wHash
|
ff602060f8b830ff |
|
VISUAL
colorHash
|
02000040007 |
|
VISUAL
cropResistant
|
630300c0820a8644,00a91aaead989600,70e0d4a2a2d4e0f0,000162c2b5b90d04,6073f3a93a329a9a,60000000282b2b53,00400e6969690640,80824cc8c86020a0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.