Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FF33DB606138683F215371D7E7B83F16E291C24ADACE259167EF83ED2AB3C01ED525D8 |
|
CONTENT
ssdeep
|
384:JQrII1Mza4OhEgJnnEjbPOEcX/qhE59T5aiHORvxQq0AusFyJMYPmnwQGI1kJc/+:JqII1Me7ZrdHO/fMIKJcomiUYTzS0t |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c3a9b4a6c1c9ecb4 |
|
VISUAL
aHash
|
ff00003820201c00 |
|
VISUAL
dHash
|
9cf8e0d0c0e0e0e0 |
|
VISUAL
wHash
|
ff0c387c7c383c30 |
|
VISUAL
colorHash
|
38000180003 |
|
VISUAL
cropResistant
|
0004000e0e101020,f8e8f0d0c0c0f0e0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 84 techniques to evade detection by security scanners and make reverse engineering more difficult.