Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14A131EB5920CF9AEC183B3D299206B8EF67AD258FF0B01490BE8D7AC17F6D54EC42551 |
|
CONTENT
ssdeep
|
384:ITeAecfMidSKb5RkEEwUjvCkkB4j+PiO6AnIwRdDxjPj7cmgB4j+PiO6AnjLCkZP:UeAecfMidS/PZAnlTjlZAnjHnLb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
964b6935e5929339 |
|
VISUAL
aHash
|
00002e7e060e0e00 |
|
VISUAL
dHash
|
9605fccc9cdc1cc2 |
|
VISUAL
wHash
|
02007e7e7e0e8e7e |
|
VISUAL
colorHash
|
310002002c0 |
|
VISUAL
cropResistant
|
fce464d414868f9e,c4e0f8fcfefeffff,fffec2d2622e8000,9605fccc9cdc1cc2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 7 techniques to evade detection by security scanners and make reverse engineering more difficult.