Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10CF22871E0916437062344D6F0B1AF0EB1F7830DCE674D2A96FC9A85AFD2C909F295AD |
|
CONTENT
ssdeep
|
768:8xAII3fl6DvKvm9oeQY++UnR2KYj2mBNH9nWMloEhrx:qAII3t6bKvSKR2KY1B3nWE5x |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92b669cd92a689b6 |
|
VISUAL
aHash
|
ff002f3f1e380004 |
|
VISUAL
dHash
|
e1c8ccccfcf261c8 |
|
VISUAL
wHash
|
ff242f7f3e381004 |
|
VISUAL
colorHash
|
310030000c0 |
|
VISUAL
cropResistant
|
008080c1c58800a8,c2aebcb2ba9c9e96,c8ccccdcf8f361c8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 78 techniques to evade detection by security scanners and make reverse engineering more difficult.