Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15FA2B631A014693B51A7D2CDB272A73DE0E3931ADBD50419A2FC83AD47E7EA0D92351F |
|
CONTENT
ssdeep
|
384:lNy5Nswp47ItzZRv/pxl8MIIIIIWVmCvwgJ/m79FjHYJUPIYsOy2+y9BH4cCUIe:lNy5NswGGzIIIIIWVmCvwg/m79FjHYJu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c36bec32b049f586 |
|
VISUAL
aHash
|
000020000400ffff |
|
VISUAL
dHash
|
1d4bc34bcc3c7100 |
|
VISUAL
wHash
|
00f1f9800f00ffff |
|
VISUAL
colorHash
|
39001200180 |
|
VISUAL
cropResistant
|
00201696960c2000,7100a00170b08000,9d0bc3434bcc3c71 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.