Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15FA2A63250102A3F62A383DDB362F72EA1D3A248D7DA181A57F8475E87E6ED0CD1345B |
|
CONTENT
ssdeep
|
384:0Cy5NpYhVbYZgEqXb7sO76LIIIRP4gnHa/9wbnYXRXpOQ+tQJ7cdmfIYsOy2+y9x:0Cy5NpYpb7sO76LIIIZ4gnHa/9wiRXp3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8309bc32f16d96cd |
|
VISUAL
aHash
|
000020000004ffff |
|
VISUAL
dHash
|
97d7c3c3c94d4300 |
|
VISUAL
wHash
|
00333171200fffff |
|
VISUAL
colorHash
|
39c00010000 |
|
VISUAL
cropResistant
|
fbdf696969dfffff,0080801858808000,8fd7cbe3cbcdcd4f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.