Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T156B3FE23415939274437C2C1347A5B3BD1B6D98FFAA70A405EECC7F62AFACA0705B159 |
|
CONTENT
ssdeep
|
1536:yEltpR4nXBKpSpFl26vaag522wywoT+swWaMGvLdY:jUMgg5VT+sK+ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9757e81c19c54f70 |
|
VISUAL
aHash
|
00040004001effff |
|
VISUAL
dHash
|
686ccc5cbc7c0023 |
|
VISUAL
wHash
|
00062e0e043fffff |
|
VISUAL
colorHash
|
07000000c00 |
|
VISUAL
cropResistant
|
616aaa0b36849c4d,0002412121410200,8000619191210080,0000419191014180,d6922a98842aa694,6c000957564b2b2b,786c4ccc7c5cbc7c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 115 techniques to evade detection by security scanners and make reverse engineering more difficult.