Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DD6100247008451B12332FC4B9D5DB1AB8C3E70FCB179524A1FEA3ED4BE9ED1C9A0625 |
|
CONTENT
ssdeep
|
48:yBhfmTmFGEcLc9corj779/D0y5+ogZKx1TNfOBLFwGUzb/BYbqoh4H0s0Ylv2isq:ybVdS03WypgKbTxO3wUb7dHYwO8OpQ2V |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9999d6c666666899 |
|
VISUAL
aHash
|
18ff9981ffc3ffff |
|
VISUAL
dHash
|
16f0330f70140000 |
|
VISUAL
wHash
|
18db19010f0f0f0f |
|
VISUAL
colorHash
|
00000038000 |
|
VISUAL
cropResistant
|
16b2330e70000000,0000020200020000,00434b5151a9bd00,0049517171495180 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 7 techniques to evade detection by security scanners and make reverse engineering more difficult.