Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T182B273358441693B0693D2C9EB30675FE3C78249EE135B0AB2F89B4C6ED7E96DC42126 |
|
CONTENT
ssdeep
|
192:x59CUmXYpDiTEzCmHWhpi/wZCZjZVZ2E55KRNnAga9O6tZheaIYTtSkhgePo55yk:f9PtQjhr6Nv0MPzIYhphNo5mEO3kp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e047b0bd14af8679 |
|
VISUAL
aHash
|
0000000000ffffff |
|
VISUAL
dHash
|
9cd3c0e3910f33bb |
|
VISUAL
wHash
|
4660602000ffffff |
|
VISUAL
colorHash
|
32006000040 |
|
VISUAL
cropResistant
|
000c0e333303bf9c,d491c2d0e0e39181 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 17 techniques to evade detection by security scanners and make reverse engineering more difficult.