Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T152F144E0C144ED37475285D8EBF66B4B7792C35EDB02088197F883AB97CAC60C6255AD |
|
CONTENT
ssdeep
|
96:Tk03jzeNNeSTgG0LBrOSV8pbwvFzexXYHFkehX5X/KNytc663kPk8J:Q4jzeTkG0BVKqJDXSNyPrPd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d3793c4647391a47 |
|
VISUAL
aHash
|
00103c387e2c0000 |
|
VISUAL
dHash
|
0024a952cc491208 |
|
VISUAL
wHash
|
00ff3e7a7e1e0c0c |
|
VISUAL
colorHash
|
06001000180 |
|
VISUAL
cropResistant
|
19b068d9f3e7ce9c,cf7ef69e7e3e3e3c,2001a280a280a280,71cc8e96968ecc70,4a49589a1a3a36ac,2021a280a280a282,0024a952cc491208 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 59 techniques to evade detection by security scanners and make reverse engineering more difficult.