Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T104B19332874B571A321747CAEB366FF9E3615509C6220978ABFC1AE1CFD49698CB3502 |
|
CONTENT
ssdeep
|
96:TJIiGNM3pgqc9Zg3Pz04jWETvP15QSlik7TyI3a3spc04piHmjzoXTjNTZcXQVD4:1tGNMZsaHmyTvnI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bec847b3c107b836 |
|
VISUAL
aHash
|
fffb9bdb87870005 |
|
VISUAL
dHash
|
8a2b3b322d3c6d29 |
|
VISUAL
wHash
|
ffd9d3db87870000 |
|
VISUAL
colorHash
|
07001010080 |
|
VISUAL
cropResistant
|
8a2b3b322d3c6d29,68606c68607851cc,4cb270f071b6e6d0,2814b2b232ecd823,13316975d44c6513,1771d4e8b2d47133,40d0a3ccf427c860 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 56 techniques to evade detection by security scanners and make reverse engineering more difficult.