Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13023D93259C87B6B53C383C47371DA4FE3D69144A27AC75AF7E5832A46C0984CC3AB98 |
|
CONTENT
ssdeep
|
1536:IZjVraKB6Cor42RDPuoZgam+e3eoQ4DvKOEUjDlInj5EKEJhW:IZhGhr4fJxQimEvW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
943ac996b690e9cb |
|
VISUAL
aHash
|
ff000006063e7e78 |
|
VISUAL
dHash
|
71b2dc2c6cece4d2 |
|
VISUAL
wHash
|
ff180006367e7e78 |
|
VISUAL
colorHash
|
0a000000038 |
|
VISUAL
cropResistant
|
0001816363890006,96d6e8b0904d0f8e,f1d9098c8c8eccc4,671e386c06748191,3333c43131c6c638,32f0ac2cecece0d2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.