Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1225260309550DD374483DAF4F7F9BB1A66AAD350DB570A4673E8832D9BD2C40CE322A5 |
|
CONTENT
ssdeep
|
384:oYF7OfQY+msy9lZKkia7pYj9e+RXMxWNqME:oYF7OfQY+JpJa1YJe+32 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b246ec90bca59bd1 |
|
VISUAL
aHash
|
ff000000000cffff |
|
VISUAL
dHash
|
23c5cfed1858160f |
|
VISUAL
wHash
|
ff000105041effff |
|
VISUAL
colorHash
|
030000001c0 |
|
VISUAL
cropResistant
|
2040333300a72727,e1dc9ebf3b93e797,cdcc19d858169c2b,27cdcbefcc295858,0000100c32b2b2b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 58 techniques to evade detection by security scanners and make reverse engineering more difficult.