Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18B14316393772902507ED1C9B1FF475A21C186BCF6034A71E3AC53AE69CF9673A0129B |
|
CONTENT
ssdeep
|
1536:igeeeDeeeeIeeee6eeeemeeeeeeeeeeeeeeeeeeeeeeee1eeeeeeeeeeeeeeeeeC:eufY57r64pu29ugKpqEgQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b26c739b1c316cc3 |
|
VISUAL
aHash
|
006042427e7e6e7e |
|
VISUAL
dHash
|
23c686a6f0dccccc |
|
VISUAL
wHash
|
0062c3427e7e6e7e |
|
VISUAL
colorHash
|
06000030000 |
|
VISUAL
cropResistant
|
23c686a6f0dccccc,0000000000000000,66e6732b3472f377,8f8f0f2965757a7a,e3ebace4e4ac2c0d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.