Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11AE1E9B14200CA7A20C2CAE8FB607B67B5D691D9EC930D14A7FA87691EE3EC6D855D40 |
|
CONTENT
ssdeep
|
192:O0rbnt2n5GGsr372tzFgFf7j3sLtlp7pD8:O0Pn7ytxgFfHubu |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c8c2f63c8d35358d |
|
VISUAL
aHash
|
fdfdfc7818000010 |
|
VISUAL
dHash
|
99c9c9f2f3b18171 |
|
VISUAL
wHash
|
fdfdfc7818180078 |
|
VISUAL
colorHash
|
130060000c0 |
|
VISUAL
cropResistant
|
028a96e4e4a4d8d8,ccc1d90d5d36f373,9694a8a4b29398aa,046068785c595959,99c9c9f2f3b18171 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 16 techniques to evade detection by security scanners and make reverse engineering more difficult.