Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19F5309B3C0C2567B03B3E3E8FA419F19B79CA146C94256A9C3E9C25E57C2EB0D47925C |
|
CONTENT
ssdeep
|
1536:j724OPStUaQ4dfrGdimjKznKrTkSrj2SrTTSrHOSrRljvuR9oP7be:W4Oc4Hj0jlPHe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c6846bd839d3b433 |
|
VISUAL
aHash
|
3c3e3e3e047c7c00 |
|
VISUAL
dHash
|
f0e4ecf4d4d4c9c1 |
|
VISUAL
wHash
|
7c3c3e3e147e7c00 |
|
VISUAL
colorHash
|
01007000000 |
|
VISUAL
cropResistant
|
f3e9bcbeffdf7f7f,93137b797892b078,b2e4171b48ccccc4,d4d6aa8e3a9e9e8e,f0e4ecf4d4d4c9c1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5 techniques to evade detection by security scanners and make reverse engineering more difficult.