Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15FF21036A044A93F11D7D2C677B06B5EF2C6E24ADA971716A3F8831D0BD7ED0CD21852 |
|
CONTENT
ssdeep
|
384:bMGQGMmG0jgO+IS+cWY82CT8RRveiNDTcRdEAC1sYFmV2gmEYAzDsFGqL3y:QGQxmt+IaUoRRvegDfgiAHsLL3y |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d269c916ce1f9e44 |
|
VISUAL
aHash
|
ff000000000400ff |
|
VISUAL
dHash
|
63928c4cc4cccc69 |
|
VISUAL
wHash
|
ff40c624762604ff |
|
VISUAL
colorHash
|
39000218010 |
|
VISUAL
cropResistant
|
708d004b43434300,4041840929815040,002004787272300c,928c4cc4ccccdc29 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.