Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T184536031A504AE3701C78AD8A236475A63EA8385C6131688BAF9C3F95FDFC6DCD37158 |
|
CONTENT
ssdeep
|
1536:JsIxWQo4u+Fj3FjzFjUzjjO/NSa7UTMtJvm:Jq4u0jVjRjUzjKNSa7SMfm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e512eddae8926392 |
|
VISUAL
aHash
|
ff0021208180fffb |
|
VISUAL
dHash
|
dcc6cacf0f0f0b02 |
|
VISUAL
wHash
|
ff020121a1c1fff3 |
|
VISUAL
colorHash
|
09200030040 |
|
VISUAL
cropResistant
|
8080808000c08000,9c9888c0c0c0c0c0,cb4f070f0a960b02,dce6cacfcb4f0f0a,3525252c2c787c18,010101100c3232b2,000000000c123232 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 108 techniques to evade detection by security scanners and make reverse engineering more difficult.