Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11F6312B2254B496FDA4781C6EF692F89A1C7934BC6525C48BBF24347DF82D24FC5E220 |
|
CONTENT
ssdeep
|
768:cV1ZnTwHfqQf4+Swh2+uFd6bXqOaKF2nDUfA+azO4JO3qxjC5ZNHwauJScM7S0e4:KnTw/qc4+S/id |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e81687b070cf1779 |
|
VISUAL
aHash
|
ff98000000fffffb |
|
VISUAL
dHash
|
26313131919c4313 |
|
VISUAL
wHash
|
ff10000000fffffb |
|
VISUAL
colorHash
|
0f601000040 |
|
VISUAL
cropResistant
|
2320313171313191,7131b1909c033313,0000000616161600,3171713331919492,e8faedf3f8bee7f9,3e1a0a9d181c0747 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 92 techniques to evade detection by security scanners and make reverse engineering more difficult.