Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1188352715157453B4257A0C2A7392F4EA3CAC34BC6521A89FBFA439AEFD2D28FC17250 |
|
CONTENT
ssdeep
|
768:mJZ7viJBJBse+fZHzaDbcduhPty0gKIBKen8QT/rifyzJZl2V1Bp2XHiALaaJCKF:pdR1m5ZcW779F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
920eed4c930ef34e |
|
VISUAL
aHash
|
0000042c0e0400ff |
|
VISUAL
dHash
|
7134ede8cccc32dc |
|
VISUAL
wHash
|
00047f7e7e6c00ff |
|
VISUAL
colorHash
|
30601018000 |
|
VISUAL
cropResistant
|
f0c0911296a4c8f0,08a04ededcdccc4d,3134edcde8ccdc32 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 173 techniques to evade detection by security scanners and make reverse engineering more difficult.