Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10F633BE06944FD3356F34097605FB246B3BE190BF90D09607648CACAB7FA82762677B1 |
|
CONTENT
ssdeep
|
768:oX/T0TQH7YFc5UcSpYu/lROtMR6rAH3pYu00XVzc+b42NB2jIGrTnzq8QE12OlDX:oXdZCOtMR6rAHevKzQ2N0msQw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c7e4303b613cc6ce |
|
VISUAL
aHash
|
426e7e00383e0c3c |
|
VISUAL
dHash
|
94d4c4c6486839c8 |
|
VISUAL
wHash
|
43ffff20283e086c |
|
VISUAL
colorHash
|
08000000188 |
|
VISUAL
cropResistant
|
fffafffffefffeff,80848c8c8c808031,99317382038b9e9e,e0cc8ca6a6a6a696,94d4c4c6486839c8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 34 techniques to evade detection by security scanners and make reverse engineering more difficult.