Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10BC34DB0371CB96E65B343E6A1DB7202733D4127E40E8C346368ECA57799C99A46BFC4 |
|
CONTENT
ssdeep
|
1536:vXj2dWl+JJJukJugtccccYccccYccccxhFTVq53QSoHxh8N6FmbXhjaPnQsR+Fun:/KFTjzmN6UbtZ9S |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d353ec6d99920c93 |
|
VISUAL
aHash
|
fd000c0c0000ffff |
|
VISUAL
dHash
|
23c8dcd8d8234c08 |
|
VISUAL
wHash
|
ff202c0c0c00ffff |
|
VISUAL
colorHash
|
030000001c0 |
|
VISUAL
cropResistant
|
00632b2b2b020000,398949400a8a1660,ac6d4b5b5bdb4f86,08000c0e16000824,00c0d8dcd8d8e840 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.