Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1ABF11F38380634A200378BD5F4918F4D3763E739D6951A197BA507A26FC9CF98AB17E8 |
|
CONTENT
ssdeep
|
192:Y2oyb+gSbcCtC8mE/saDe++saZEFGnsvENfYNqyTzhBeC3L:HoZcCtCo75+xEF6jCtTzhBeC3L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
980da3e732f8701f |
|
VISUAL
aHash
|
7f18181800fcff5f |
|
VISUAL
dHash
|
edf2b2b2b280f3bf |
|
VISUAL
wHash
|
7f18181800fc7f5f |
|
VISUAL
colorHash
|
020020000c0 |
|
VISUAL
cropResistant
|
338df2f2f2b2b2b2,803100c8f333bccd,cdf2f2b2b2b0c030,0000203232300810,d571994b1999e2f9,f0d4777bfcd7b313 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 34 techniques to evade detection by security scanners and make reverse engineering more difficult.