Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19584F7A2F31016B8258B0BCDD1A1652831D6A2DEF37792ECC7F646A1F915EF0286C53D |
|
CONTENT
ssdeep
|
1536:CzkKMaR0KUBhs8IQTI0MZw8VNSeCkydLAWozgKMaR0KUBhs8IQTI0MZw8VNSeCk1:ld+oDCuBn40M2Tk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec9d13e2129dbb12 |
|
VISUAL
aHash
|
fffbfbf3f3f30000 |
|
VISUAL
dHash
|
061636272707269c |
|
VISUAL
wHash
|
fff393d1f1f10000 |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
12063636272727a7,5c2c3d5c793b1f0f,27230727360886c8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 22 techniques to evade detection by security scanners and make reverse engineering more difficult.