Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1AC13A633A04862764B62AB83BA7433AED37301DFC2506D8A60A5475DFD91DBED5930E3 |
|
CONTENT
ssdeep
|
384:ci6Ee0buK3QNO8xlZlxK51vb3nrPv5TPc9SBaEiUK1VAkPcjwenFLkL7DsrdTeOr:ciNWTAFotztiCfHo |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c13ec8c1f336e6c2 |
|
VISUAL
aHash
|
000000007c7c7c7c |
|
VISUAL
dHash
|
b17261f1d9d9d9d9 |
|
VISUAL
wHash
|
ff1818007c7c7c7c |
|
VISUAL
colorHash
|
07007000000 |
|
VISUAL
cropResistant
|
25b2936d4d4f2c4d,e0d6b6c8e0d6b6d8,b17261f1d9d9d9d9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 17 techniques to evade detection by security scanners and make reverse engineering more difficult.