Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F3D3EC30BA324A22109F31DEA227535D62D383C6D35217F975B8C3789BBDD54BEA3198 |
|
CONTENT
ssdeep
|
1536:4eCGsIxrq9WOlEnyPwbokwO3RG7pwO3bGe4wO3mGASLyO4mBdQqTGFra4mBeQqTn:lfiWqPCnnLtEWx7MfP90B7n2L7EzU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c258bd4a9d32a6bc |
|
VISUAL
aHash
|
ff400060200084ff |
|
VISUAL
dHash
|
81a28cccc4cd0d32 |
|
VISUAL
wHash
|
fff840646020e4ff |
|
VISUAL
colorHash
|
06403000040 |
|
VISUAL
cropResistant
|
81a28cccc4cd0d32 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 74 techniques to evade detection by security scanners and make reverse engineering more difficult.