Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15C9374706301553F516793F1B2A1EB5EE1BAE34ACA279A4CB3FC41932FCAC89DE15250 |
|
CONTENT
ssdeep
|
768:Hbi61IU/6Rx8K9pm6UzBz8Z+AXVDLDOrurZ9dI+ekNK/cRuymAKVT4g5:+61IU/+x8Kjm68BIZ+spNVXE |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93a4ece1929cc5ce |
|
VISUAL
aHash
|
ff007c2c2c60040c |
|
VISUAL
dHash
|
de3ce0e9c9cc3868 |
|
VISUAL
wHash
|
ff047e3e0e6e041c |
|
VISUAL
colorHash
|
3800e200000 |
|
VISUAL
cropResistant
|
ffffefcfcfeff7ff,968e8e8ea8d0f260,befeff2b23fffefe,d6f4e0e9c8cc3868 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 30 techniques to evade detection by security scanners and make reverse engineering more difficult.