Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T193A2C73260142A3F12E3C3C87771FB2DA1D39288CB861D1563F8475E4BEAE90DD1A95B |
|
CONTENT
ssdeep
|
384:7Oy5NgO+VteKuXlQjuGIIII/5WLIINiFSYM/oajFKj4Ujqm4mQe0loDnIYsOy2+o:7Oy5NgOuuGIIII0sINiFSYMg6FK40R42 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c347bc3ae14992c7 |
|
VISUAL
aHash
|
000030200000ffff |
|
VISUAL
dHash
|
9844c4c2c9edc300 |
|
VISUAL
wHash
|
00f0f4702105ffff |
|
VISUAL
colorHash
|
39000200030 |
|
VISUAL
cropResistant
|
0280800070908000,9812ccc4c3cdcdc3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.