Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T185F22E366084AD3F02D783CAB775AB1EE3CAE245CA671B59A7F4831C0BD7E90CD21552 |
|
CONTENT
ssdeep
|
384:bMKermMmGDAskO+IS2cFcY82L+18z6tMvFMebqKm6YZ+iJk5DiRVbEqG3H:QKedm6+IwRBOtMtMuiRVXG3H |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d66dc9129b379a44 |
|
VISUAL
aHash
|
ff200000000000ff |
|
VISUAL
dHash
|
7bc2844cc4cccc69 |
|
VISUAL
wHash
|
ff704604762604ff |
|
VISUAL
colorHash
|
39000210010 |
|
VISUAL
cropResistant
|
720d004b43434000,4041800929815040,002004787272300c,c2c44cc4ccccdc29 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.