Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T183D2303750444A7F01E796CABBB1BB1DE2D6E589CB531A5663E8875D03C3EC0CD3286A |
|
CONTENT
ssdeep
|
384:ThOJEHG9n0Jh+IGd9TPHASD+aLbggaRgxG0Iq:ThEEHso+I2M4+aLbggaRgxOq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f2dd8d02bf1238a9 |
|
VISUAL
aHash
|
fffcc8c4c44444ff |
|
VISUAL
dHash
|
3830302c0c8c8c22 |
|
VISUAL
wHash
|
fffcc0c4c44444e7 |
|
VISUAL
colorHash
|
0f001408008 |
|
VISUAL
cropResistant
|
3830302c0c8c8c22,c68393a0ccf83438,eee5e6f0c18d4899,0006094969616906,e0e169b918191959,d0e8749becf7eb75,69696969e9b2b2b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.