Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19D343AB02201357F71778BE5F5B6672E71BED30AD81B8918A3ACD6A637C9CC8D417A40 |
|
CONTENT
ssdeep
|
1536:mcBinkIEIIXNDnI1M4GYzp6GIJQCXoDeNeLewG7eYDCTwoIg+VEIhXN+FctkYIJn:mI4XGIUA8+GCWsbkXexMAQgDnAMervq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9852b236db0cf333 |
|
VISUAL
aHash
|
0400181c1c1a00ff |
|
VISUAL
dHash
|
68b0b0f072d6f6cd |
|
VISUAL
wHash
|
041c5c7e3e0e12ff |
|
VISUAL
colorHash
|
30001600008 |
|
VISUAL
cropResistant
|
888488888c8c8c8c,68b0b0b070d6f6cf |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.