Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16C2405766045E8B740A3DAC5A1B5571F22A9E71BCD0307C3B7F8A3AD5FDAD88ED22410 |
|
CONTENT
ssdeep
|
1536:D28WIIcII5JTD+iNnhCxL/9xF1gZZhoknSz6910sJLZLob4HpGiQN1fY+GjKt37U:FJTD+iNnhCxL/9xF1gZZhoknSz69LN |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
936c7d9793526168 |
|
VISUAL
aHash
|
00ff003c7e3e3e3e |
|
VISUAL
dHash
|
6b2bc4d8d8d8d8d8 |
|
VISUAL
wHash
|
00ff003c3e3e3e3e |
|
VISUAL
colorHash
|
03000000e00 |
|
VISUAL
cropResistant
|
0080216168163626,2240232b2b234023,98d999d9d9d9d9d9,696136064194ccc8,84c4d8d8d8dcd8d8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 15 techniques to evade detection by security scanners and make reverse engineering more difficult.