Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T153636532D3931912907BC1D8B072478D2352868DC7574F79A7BE63BAF9CFCB62612258 |
|
CONTENT
ssdeep
|
1536:D8fNQ0eeZeepQhpzyseuek57rl4pTeM0eHde4e1rS1tFACoeee7deBC/sgHeQODp:Vf57rl4p1/J/P/mDMq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
906d6d791a939cb2 |
|
VISUAL
aHash
|
00c34e46466eee7e |
|
VISUAL
dHash
|
9282ac8c8c8ccccc |
|
VISUAL
wHash
|
40807e4646eeee7e |
|
VISUAL
colorHash
|
06000038000 |
|
VISUAL
cropResistant
|
9282ac8c8c8ccccc,000103061c3a74c0,8040201088482513,32929292408d8588,33b33329b4f4342e,0144052304017164,0004880400000101,112a67d5f0e9f161,420103061c3a70c0,9793931323271b3b,0140002090482533,6b69a4e4e4a42c0d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.