Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15103523250449A3F16D382C67BB46F1EF3D6D24ACA53169A63F8831E0BC6EC0DE31956 |
|
CONTENT
ssdeep
|
384:H+jkYvbHCDd3R+ISVc/AeFXUu0OEUYHjdmbW19j1nHMAXCidS8wJal+Ut/vqo3X:H+gYvDu+IhKuEVjobG9pRpdSJJY8o3X |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8e7ef106d91c9c32 |
|
VISUAL
aHash
|
ff000018183000ff |
|
VISUAL
dHash
|
23477570f1e5d5ab |
|
VISUAL
wHash
|
ff001c3e3c3c00ff |
|
VISUAL
colorHash
|
0a038000040 |
|
VISUAL
cropResistant
|
020c02222322020d,739353c5c596b1b1,a02b800b0b832820,0008146970702004,47457171f1e5d7ab |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.