Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16CE2A873A120653702B391C6B2627B2AA2E3074EE983150596FD43FD0BE7D15EF2B716 |
|
CONTENT
ssdeep
|
768:/WQvvC5jr+C3YCLnl5p1bLp55PF1X9XVlzNjrZD55leOW1Pp1lL5h5xuhbY7sOy8:+QvK5jrlnLnl5p1bLp55PF1X9XVlzNjg |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d636b464e505d5b4 |
|
VISUAL
aHash
|
000000000000ffff |
|
VISUAL
dHash
|
d418ccc0c0c8c800 |
|
VISUAL
wHash
|
46040e707064ffff |
|
VISUAL
colorHash
|
31018000600 |
|
VISUAL
cropResistant
|
0080880458988000,d49cecccc0c8c8c8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.