Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17283EBB140449C3790D3E6E09671AF2F72C6D34ACE0B070697FA979E4FC6DA1DE261A1 |
|
CONTENT
ssdeep
|
768:GI9sEj+ORyUC5mgwcX/8gd/GRauEEPwOicOJBByiA5Wgn/yRTlEcPkIBITOuVn/:iG+OIUCnJCMaOuVn/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f152ae9ab8db8324 |
|
VISUAL
aHash
|
ff000040c3ffffc3 |
|
VISUAL
dHash
|
3986d69896689696 |
|
VISUAL
wHash
|
ff000000c3ffffc3 |
|
VISUAL
colorHash
|
07400030000 |
|
VISUAL
cropResistant
|
5958160a2e2688a0,86d4d89696699696,2659197979d91924,a0cece96c4d8d899,b2b2b44864b68082,6db6c8b6ec926c4d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 73 techniques to evade detection by security scanners and make reverse engineering more difficult.