Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AF235A726332B4B843DB91DEF7382E46B2D29889F9C74594B5C55ACD23C3C806297BB4 |
|
CONTENT
ssdeep
|
768:aZ+EsZx8/G8sQRF4PDawDM5BUwbM5BtwzqN2/y9dGDUDF1E56ITmH+LXPnTyPqD4:aZ+EsZ/8s6OPDawDM5BUwbM5BtweN2/s |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ee914abc43b54b61 |
|
VISUAL
aHash
|
ffffdbffff998100 |
|
VISUAL
dHash
|
6931337763232f41 |
|
VISUAL
wHash
|
fd9f9993ff910000 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
6931337763232f41,8601a1a59585b524,f0cc96b2b2b2cce8,1c1c1cc080e0c0a0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 18 techniques to evade detection by security scanners and make reverse engineering more difficult.