Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18EC200B25347092FEF4B80CAFA552B89E1C6A36BC2514C45FBE2851BDF81E24FC29171 |
|
CONTENT
ssdeep
|
768:+MXspT29rmuw10XNrzGNt9Zs+GPTnZwbbQNKh2p+ohCyoxaSrE0X1Xmh2fld1Cll:+Yspa9rm1XvgF |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d14ab52eb4aa51cb |
|
VISUAL
aHash
|
000000000000ffff |
|
VISUAL
dHash
|
94d0d9ccccd0a1b0 |
|
VISUAL
wHash
|
407c7c3c2000ffff |
|
VISUAL
colorHash
|
39007000040 |
|
VISUAL
cropResistant
|
00000030b08a1a9a,d494d9d8ccccccd0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 152 techniques to evade detection by security scanners and make reverse engineering more difficult.