Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19C33DE30A880D83B01CBAAC85A72672A62F64345C5170699FAF5C3EE1BEFD5DCE73405 |
|
CONTENT
ssdeep
|
1536:LCJs2R0acC9WaGJC9tYusfbelWf0crXFuI+4SzCfH7RF:emacGWaGJGtYusfbelWf0crXFuItH73 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9505af1e5af23525 |
|
VISUAL
aHash
|
003246780000ffff |
|
VISUAL
dHash
|
3de68e90f8f44d08 |
|
VISUAL
wHash
|
003e6e7c0004ffff |
|
VISUAL
colorHash
|
03080003040 |
|
VISUAL
cropResistant
|
2be2cece9e90e0f8,fef6f4f40c4d0a0a,34c3cc2c4c0c0304,e6ce9e98c0f8f6f4,0b3d36b6fcddd5f3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 104 techniques to evade detection by security scanners and make reverse engineering more difficult.