Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DFB226BB8A8550DB3A15B2D0A5532E5C9887CC4E55E28A0D57FFD2A4F362CF6F913308 |
|
CONTENT
ssdeep
|
384:+PU8UBUvmAYxBmQXJu0/70LEUOezArtIVWeP/96IZwiGFn:+cpUvmAYxu67UBDArtoWet6IEFn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
db8e261b757c111a |
|
VISUAL
aHash
|
003f3df8ac0c00e2 |
|
VISUAL
dHash
|
53e3e9aa18d8bb4e |
|
VISUAL
wHash
|
003f7dfeec4c08e2 |
|
VISUAL
colorHash
|
1ac00000000 |
|
VISUAL
cropResistant
|
0484c4c0c766ecf9,f0b1d27430c880c1,e081c0a1a8a5a5bd,e0c9818c2a862ca2,53e3e9aa18d8bb4e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.