Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AB437632D216150341A7C5D9F1629B4E32928789C7174A71B7F853BEBECECB66B2128C |
|
CONTENT
ssdeep
|
1536:lz9Up9Ug9UM9U99UcVQLNSSePEXeRPtQKPUgOd61eOtpQjYa3UeeQBSlkV6CoJKq:REwPUgOd6W3Lz6bB3v |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b4cdcd3cb8d0c8c3 |
|
VISUAL
aHash
|
c383ffc7c787c7c7 |
|
VISUAL
dHash
|
16060e2d2d2d0d2d |
|
VISUAL
wHash
|
8383e78787878787 |
|
VISUAL
colorHash
|
06200038000 |
|
VISUAL
cropResistant
|
16060e2d2d2d0d2d,91d2b2b0a9a0a2b2,d948a4e1302e3a22,d73368cc6c86c261 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.