Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10EC251314090BA3B0283D3C9B770A75FA3C6825ADE134B06B2F98B4C6FD7D62ED56525 |
|
CONTENT
ssdeep
|
384:L98qAeFjhYXcq9Gg/uBH+xGrIbvBphrP5J1KMOu+f:L9S0jhYXcqkCuJrIbvBp9hSI+f |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9616e9ed16968569 |
|
VISUAL
aHash
|
0000040400ffffff |
|
VISUAL
dHash
|
9cd3ccec8c0f23b7 |
|
VISUAL
wHash
|
0000662604ffffff |
|
VISUAL
colorHash
|
33006000040 |
|
VISUAL
cropResistant
|
301a80587c006c0c,000c0e333323bf9c,9cb1c8ccccec8c8c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 17 techniques to evade detection by security scanners and make reverse engineering more difficult.