Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14E22B77A518049374293D3D1BFC96B259247808CEEC4CBF1D2FE42A8E3CDED9D096955 |
|
CONTENT
ssdeep
|
192:ElLWhq44+H+PuYRzeq8n5SgXQaqfoj0U42Jt/FdWVqFWrdK:Elyhq44acuYMt5SgCgv4CGVdrdK |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e61b1c19664f649b |
|
VISUAL
aHash
|
00ffe7e7e7efffe7 |
|
VISUAL
dHash
|
4c1c0c4e4c0c788e |
|
VISUAL
wHash
|
00c7c3c3c3c7e7c3 |
|
VISUAL
colorHash
|
06002018001 |
|
VISUAL
cropResistant
|
4000606860004000,1c1c4e4e0c10488e,0040012121004000,4f0d151496969616,2f4396940c0c1c1c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 223 techniques to evade detection by security scanners and make reverse engineering more difficult.