Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T163233323E75259162177C8C8F167975E2285838ECA030B7173EC97B96ECECF67A51388 |
|
CONTENT
ssdeep
|
1536:O9nKejJUCGPAw7CDzazxz4zDzkzb+32HczsB1AeeKsaleZUsAfbOBMReeK9PJAB4:OFutkH4gczCgvZQBuQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e96c6192c99a93b3 |
|
VISUAL
aHash
|
c3c1fbfbefffc3c3 |
|
VISUAL
dHash
|
2b2782f29a9a8a8a |
|
VISUAL
wHash
|
8181a97bcbebc3c1 |
|
VISUAL
colorHash
|
07000038000 |
|
VISUAL
cropResistant
|
2b2782f29a9a8a8a,711964f835172b2b,9293aead8dd4d261,4d8e17d49696964d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.