Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11423666011135D6B62C7CFE4E35CD755A09BAF58CA17CA0CFFAC42B27ACDCB98899540 |
|
CONTENT
ssdeep
|
768:a931iCACOIg84jE0JWy/vaO03eBrYEm1K+z8gA6nd6dPDfZ2OSgeHwGr8+6TQaHB:WiKzg84jE0r/vaO03eBrYEm1K+zrA6nI |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
88558a552377a377 |
|
VISUAL
aHash
|
1818181818181819 |
|
VISUAL
dHash
|
3230323030323331 |
|
VISUAL
wHash
|
3f3f1f1b1c181819 |
|
VISUAL
colorHash
|
38006000080 |
|
VISUAL
cropResistant
|
3230323030323331 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 5855 techniques to evade detection by security scanners and make reverse engineering more difficult.