Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13DB3FE234259362A4437C2C0347A5B3BD1AA998FFAE709005EDCC7FB6AF9CA0745A51D |
|
CONTENT
ssdeep
|
768:4W99tpR4nXF6YjOpSpFlTC6rrWu8IhF+19h+Xr6Rs7Ty3:7tpR4nXBKpSpFl26vzM19hgr6Rs7G3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
933dec3391626ad4 |
|
VISUAL
aHash
|
c090002e0e0ce1f8 |
|
VISUAL
dHash
|
2222295c58590983 |
|
VISUAL
wHash
|
e2d8002e0e0ffdf9 |
|
VISUAL
colorHash
|
11400030000 |
|
VISUAL
cropResistant
|
2e0084c0d0820046,9886e0b8fcbc9ebf,c680a0e0c0a08082,8680a0e0e0a28082,820084a0a0800012,2cc411038bd1f118,fa7c7cfc80b0b8be,2222295c58590983 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 113 techniques to evade detection by security scanners and make reverse engineering more difficult.