Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DF033F70D0A21ABB4193E5C8B2B55F4AB3C0C146EB27070A63F9C35E5FCBC91DD96A94 |
|
CONTENT
ssdeep
|
768:zIIIjG28i0X6Qx+eeecnJeeecE+eeecnJeeecu+eeecnJeeecOTQZQF:zIIIjG28i0X6Qx+eeecnJeeecE+eeecY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e4356a58b6a4cdc3 |
|
VISUAL
aHash
|
80c0f2f7fef0f0f0 |
|
VISUAL
dHash
|
060766262462c745 |
|
VISUAL
wHash
|
80c0f2f6f6f0f0f0 |
|
VISUAL
colorHash
|
10180000000 |
|
VISUAL
cropResistant
|
060766262462c745,76fcc2c24464465c,0406c6ecece40f8b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 54 techniques to evade detection by security scanners and make reverse engineering more difficult.