Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CF6518F8E66C61FC010F4AD486305E7C3B5D21B5B202C550C7BCE67AAAF7695C60B89E |
|
CONTENT
ssdeep
|
3072:rkZNeLTpSnScVi1DVCqyTYUegDxc9UqrP0gScEAnlj6cR/gy1U67X:rbCS9yp2JuA5E67X |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e246b9bd968383a9 |
|
VISUAL
aHash
|
ff00000000ffffff |
|
VISUAL
dHash
|
2c32c4cc2b0a331b |
|
VISUAL
wHash
|
ff00000000ffffff |
|
VISUAL
colorHash
|
06000000006 |
|
VISUAL
cropResistant
|
4c4c300023270004,e08c97c0fc368ee0,6094919494919060,b27169cccccc9696,5343733389894b4b,0c0a1b3b331b033b,243ee6c0cce43d0b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 83 techniques to evade detection by security scanners and make reverse engineering more difficult.