Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T100A458F30190EB394B76D3E42A30B31D978FB2CBBA4099DFC68E152569D47E1A422CD5 |
|
CONTENT
ssdeep
|
3072:9CaDECrE0e+uyqkKokLRkVygyWUQqfKSx0WzfGXIzU:9CagC1hqkKokLRSSx0WzfGXIzU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b6c13836c9eb3478 |
|
VISUAL
aHash
|
7fff00ff06040000 |
|
VISUAL
dHash
|
dc4848426c0c2d0d |
|
VISUAL
wHash
|
ffff80ff1e060400 |
|
VISUAL
colorHash
|
18006000080 |
|
VISUAL
cropResistant
|
595bdcdc1c191919,a5a6a6a6a5a5a4a4,a6a4a5a6a4a4a6a5,6d8dc2c4982a1bdc,480948403c0c2d0d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 52 techniques to evade detection by security scanners and make reverse engineering more difficult.