Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D992BCE0D450F93B471781D9B7B26B1B7791C789CF030A54A3F493AA9BC9CA0CB2249D |
|
CONTENT
ssdeep
|
384:O+eaukQzpc1jvAd36g/9UOA9G4xtwSK/M00pLYGPiku0jK8MkleN8F:peaukQFc1jvht9G4xtwSKkVpLYGKku0n |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e3781c52b243d774 |
|
VISUAL
aHash
|
f8d8f0e1e5e02077 |
|
VISUAL
dHash
|
2931020b0dc9c9e6 |
|
VISUAL
wHash
|
f0d8f0e1e5e0207f |
|
VISUAL
colorHash
|
06c00000000 |
|
VISUAL
cropResistant
|
131a002222a3f3f3,f8f8e0c8c0c4f090,372667676062e243,f6e6eccc4e383c38,cfccccbc2cceccca,2931020b0dc9c9e6,195d4b5998587838 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 61 techniques to evade detection by security scanners and make reverse engineering more difficult.