Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10574D7B1C154427E1283D3E9A726A32EB39F91E8F66383558AEF477C5A8BC58FC03544 |
|
CONTENT
ssdeep
|
3072:UG/t5lN7ojrXhp82aXpnogVg7zOWdrOG/zVzCRnuqcI+OgeHAJMyh7T4S95O+ciQ:Wr4bJRISj+s |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b836cb1c43665967 |
|
VISUAL
aHash
|
20c78787c79fc7f9 |
|
VISUAL
dHash
|
c23d3d2d3d332d5b |
|
VISUAL
wHash
|
00878787878fc7f9 |
|
VISUAL
colorHash
|
06000030040 |
|
VISUAL
cropResistant
|
3d3d2d0d37352d53,9a0e3232332c34b2,0283a30000020200,76bbbb5b089adefc,0101c9d9d0450301,f8f0c08101010101,0008a0e481b04d71 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.