Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B8738331A504EA3B01C796D8A632472AB3EA8341D6530689FBF8C3E91FDEC6DDD32554 |
|
CONTENT
ssdeep
|
1536:y4GsIxM0UpFFgOFFrpFFb+C8V1OJ1Sjd7UTMvP2AzW:uo0OFPFPFsV1OJ1Sjd7SMGAzW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f3326c1a6ddc4598 |
|
VISUAL
aHash
|
00e7e7e68400ffe3 |
|
VISUAL
dHash
|
cccccc080a484b82 |
|
VISUAL
wHash
|
00e7e7e68400ffe3 |
|
VISUAL
colorHash
|
060c00000c0 |
|
VISUAL
cropResistant
|
cccc8c080a48038a,cccdcc8c8c080848,5070606460484840,a9d1d3e1e5134393,0000000008123232,000000001432b2b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 102 techniques to evade detection by security scanners and make reverse engineering more difficult.