Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EC134A726332B8A843DB91EEF7382D46B2D6589DF8C74454B5C95ACD23C3C806297BB4 |
|
CONTENT
ssdeep
|
768:aG6Ch+EsZx8/G8L46Daw3MIB2wVMIBOwZUcix+y9dQpUDF1E56ITmHDLBABW8KPS:aG6Ch+EsZ/8k6Daw3MIB2wVMIBOwZUX6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
aeb4c9d285c1b7c1 |
|
VISUAL
aHash
|
87818181b585b981 |
|
VISUAL
dHash
|
2727572d454d515b |
|
VISUAL
wHash
|
ff818181f5a5f981 |
|
VISUAL
colorHash
|
32000000030 |
|
VISUAL
cropResistant
|
2727572d454d515b,ecf0b1b4c869b0e0,a2d29a52451d5525,aa8b5564645c2626,26265fa5c4c4b0db |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 18 techniques to evade detection by security scanners and make reverse engineering more difficult.