Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T111D392D55618038CA14BCA7CEF2FFE05131FB1AABA558680299EC26C96CF8D1F71752C |
|
CONTENT
ssdeep
|
1536:XO0RQ7H+72+ZVmxXBZkgc1ztsuHahWmRGJjlFsR8MLqc/XFsR8MLqce00:e0RQ7Hc2WVmxX3kgc1ztsqa5wcWc |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
91ecee91e294adc1 |
|
VISUAL
aHash
|
ff00000e4f0f0e00 |
|
VISUAL
dHash
|
03831e989a9adc23 |
|
VISUAL
wHash
|
ff000e6f6f0f0f01 |
|
VISUAL
colorHash
|
394010000c0 |
|
VISUAL
cropResistant
|
0000000000000003,fca4a4b4f4dacec3,0000000000020408,60c4c48480828281,03a8fc889a98dc21 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 150 techniques to evade detection by security scanners and make reverse engineering more difficult.