Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18392C5F19144140A322BDA84A992BFCD72668607C70F096BFAB9245AF6DEDF4C176381 |
|
CONTENT
ssdeep
|
384:fsTodwBSiSpy2dLcj8RNNx1dHfZudfOryfXNk9Gs902dtnsbj76NN71d/ogfMrd3:frGBjwzB289x1ZfZudfOryf6As62dtsp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b65c41433e36d9c3 |
|
VISUAL
aHash
|
0000ff83f7ffe727 |
|
VISUAL
dHash
|
24661f262f8cce4f |
|
VISUAL
wHash
|
0000ef83ffe7e703 |
|
VISUAL
colorHash
|
07000000180 |
|
VISUAL
cropResistant
|
64661e266f8cce4f,39fe881cf0b818da,0000404040404080,6575625449566d59,3b0d8545d3d20603,ae3d155331393939,8116696970714d2b,0000000000000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 16 techniques to evade detection by security scanners and make reverse engineering more difficult.