Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17193C621B152281B00274BD5F663BB9C334A529AD44306B0E6F927A4EFDECF4359772E |
|
CONTENT
ssdeep
|
1536:mthk9gjdpd5q9GjheAegAVl3gr0X5AW4j3nZI3OpZE9FuT5isze8Vl1:bsYYAP9qWG6+U+wv8N |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c624b9ce38b96c8e |
|
VISUAL
aHash
|
00343c003c3c3c3c |
|
VISUAL
dHash
|
2ce4e4d8e4e0f8f8 |
|
VISUAL
wHash
|
873c3c3c3c3c3c3c |
|
VISUAL
colorHash
|
30200030000 |
|
VISUAL
cropResistant
|
cad2b33d7355312d,76f6b59676adb5b6,b2b23220a0a0e0f0,2ce4e4d8e4e0f8f8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 70 techniques to evade detection by security scanners and make reverse engineering more difficult.