Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FBA2C531A0143A3F1193C3C97762BB2EE2CB5688D746091952F8476E8BE7FA0DE1345B |
|
CONTENT
ssdeep
|
384:5Ny5NCGDi2LHzYqPXIIIIIoKcppywA9MINUEIYsOy2+y9BH4cUUIe:5Ny5NCGO2IIIIIncpcwA9V7sOy2+y9Bh |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c34dfc32b16d9688 |
|
VISUAL
aHash
|
000030200000ffff |
|
VISUAL
dHash
|
1cc0e3c3cdcc8300 |
|
VISUAL
wHash
|
00f87870040effff |
|
VISUAL
colorHash
|
39c10000000 |
|
VISUAL
cropResistant
|
ffffff0b0bffffff,0280800270908000,9c44c3e3cbcccc13 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.