Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17723B73118C46F2715D3D2C5E3509A4BE3D6814CE27EC68AF5DAC32B4AC59D8C87AF98 |
|
CONTENT
ssdeep
|
768:5n04B1f+1GppvBHNXWEc+zklfKN8Eh97lSHp/Zl7lt4T03+7D8e/0k+dZ9a+EbDb:5n04B1+14ZBHJWB+wA8EhnSJ/Zl7lt4t |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
946bb491ecb390ce |
|
VISUAL
aHash
|
ff000000046e6e5e |
|
VISUAL
dHash
|
7170ccf0b49c8cac |
|
VISUAL
wHash
|
ff1800007e6e7e5e |
|
VISUAL
colorHash
|
02000000030 |
|
VISUAL
cropResistant
|
0001416363490002,1e16474713191b1a,8494c0f4b0881e5a,33e8d4f09c9c8cac |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.