Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T141C2B830B0406E3B50C7D7CCF3B2D33A66E39349D9570A0A42FE97698BE6D50ED2645A |
|
CONTENT
ssdeep
|
768:cz12y5NVocfyBlFWK8sx0h7sq0KM37ZRLR7kAkh7Lh443F7sBLy2+y9l0K4/LIe:nI1qBwF7sBLy2+UuK4/LIe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c363bc3adc08c3e3 |
|
VISUAL
aHash
|
000020000000ffff |
|
VISUAL
dHash
|
948acac2c8c9f100 |
|
VISUAL
wHash
|
00cff030202cffff |
|
VISUAL
colorHash
|
31000400030 |
|
VISUAL
cropResistant
|
30c0c4024cac8000,940acac2e0c8c9f1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.