Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14E54FE234259352A4037C3E420A95B3BD1AAED8FFAE709414EDCC7F72AF9C90741B659 |
|
CONTENT
ssdeep
|
1536:rkTct9tMbXlOJi55R+OvS0+R3/r8UH8ArXvUd0gAK6Fyz0c42JW1ROowVKqZ7p38:vMw0aF9kGj2JW1RONFGIcd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
961e6d63c1c9d29c |
|
VISUAL
aHash
|
00003e7e7e7e0000 |
|
VISUAL
dHash
|
c32f6cd4cccc338e |
|
VISUAL
wHash
|
00007e7e7e7e0ce7 |
|
VISUAL
colorHash
|
07006000000 |
|
VISUAL
cropResistant
|
ec8cb6eab08ccc32,0100000468869604,d32f2cccd4cccc33,455101f5f1d50145,22d6d529696b0a2a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 37 techniques to evade detection by security scanners and make reverse engineering more difficult.