Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A983743090A0963F026B97E4D9B5AB1B73D1934AEA130A4267FC576C2FDBD64FD23811 |
|
CONTENT
ssdeep
|
1536:Po44D4VD/42Fr/Nc4ncWXX1wRMb1qGDccGZcu6w1/JPrXYYjYtXLSe5/o2CBoSZe:Pw4iWrxc4hazkNCBoSk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
acc3f996eb06640b |
|
VISUAL
aHash
|
ff0f0030311703c3 |
|
VISUAL
dHash
|
26ffcfc767f4b72b |
|
VISUAL
wHash
|
ff0f2031371707c3 |
|
VISUAL
colorHash
|
010020001c0 |
|
VISUAL
cropResistant
|
200020272720007c,5252effbfcfe7c7c,b73f7ec236b554d9,3d8ecaca3436b131,6505252525252525,0000a8c4c4c01000,ffcfc767e5f4a72b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 53 techniques to evade detection by security scanners and make reverse engineering more difficult.