Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EF43EE30A441E82B05CBAAC86A72672A63F64345C5130699FBF183EE5BDFD5DCE33506 |
|
CONTENT
ssdeep
|
1536:IVJsIxq8SelrZsLelN9csJXkl2/fcrXFuIASSo9DwONV7RF:I28SGrZsLGN9csJXkl2/fcrXFuI8SV73 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d525fa3ed1a02535 |
|
VISUAL
aHash
|
04ff227e0200fefc |
|
VISUAL
dHash
|
0ce2cecef6fc9d11 |
|
VISUAL
wHash
|
00ff667e0200fefc |
|
VISUAL
colorHash
|
03080003040 |
|
VISUAL
cropResistant
|
36b0e6cecedac6fe,fef6f4fc11180119,34cbcc2c6c0c0304,e2cececac6fefef4,0f3d36b6fcddd5f3,8a13838a5e8f8e84 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 103 techniques to evade detection by security scanners and make reverse engineering more difficult.