Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T190B3FD23415865270437C2D1347A6B3BD1B6998FFAE70A014EDCCBF62AF9CA0B42B15D |
|
CONTENT
ssdeep
|
1536:PubtpR4nXBKpSpFl26vlBZ0QlO+wU+TICr2SPv8s1:sUMc+n2tCGa |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9212ed4c5ced6d61 |
|
VISUAL
aHash
|
0004040404ffffff |
|
VISUAL
dHash
|
9cccccdc9cac002b |
|
VISUAL
wHash
|
0006060606ffffff |
|
VISUAL
colorHash
|
12001000e00 |
|
VISUAL
cropResistant
|
616aaa0ba4a49829,0000402020400000,8000619191610080,00204000a0804000,aaaa583222aea4a5,ec002957562b3b2b,93accccccccc9cac |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 113 techniques to evade detection by security scanners and make reverse engineering more difficult.