Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T132C2C561D888B93F44D343C6A720166BB385D24CC7A6CAAD95F4E3AD4F87E54CCB6384 |
|
CONTENT
ssdeep
|
384:pbMJX+44TRR/4GkyAVoKfnMxl+nm100m5L/IBZNxmjl:c+44z/4GkycoKfSl+x0mt/IBXxmh |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed7c9212474f3c38 |
|
VISUAL
aHash
|
00ff81e1c1c3ffff |
|
VISUAL
dHash
|
8c0b0b030b2b8f0b |
|
VISUAL
wHash
|
00c381e181c3ffff |
|
VISUAL
colorHash
|
0ec00011000 |
|
VISUAL
cropResistant
|
cc0b23030f230f0b,800be4cceca41100,80a1918c8c9da181,0c0da1a9285edc48 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.