Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FEB34DE566CCEF3200F34092B09695CAFBB90915F7191490BE99CAD6B7C88B706F7394 |
|
CONTENT
ssdeep
|
1536:00YFEeGGlh4JC5HApP+aQbSWBvk+jmUWFX012hkq0dzQ2N0msQw:00YGeGGlP5iFvF016cVw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c391e136b436b6c6 |
|
VISUAL
aHash
|
66387c003c3c00ff |
|
VISUAL
dHash
|
d4f0d85cc8e0c0ca |
|
VISUAL
wHash
|
6e3c7e003c3c20ff |
|
VISUAL
colorHash
|
30000000006 |
|
VISUAL
cropResistant
|
8202009696060080,d4f0d85cc8e0c0ca |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 34 techniques to evade detection by security scanners and make reverse engineering more difficult.