Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T144538950B252086B227B96C5A5653F0932EBF30FC219C800EAFD52562FCBD75B8B54B7 |
|
CONTENT
ssdeep
|
384:WLU10YPTm8dAZ9X3412Ys2Yn2Rf/ZWAWCWrnYW1cYikc+3Piv9:jm8dAZ9X34HMe3ZWlnYW1cYikc+3Piv9 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b4944b4b6de4c91b |
|
VISUAL
aHash
|
060e4e8606000000 |
|
VISUAL
dHash
|
449c8c2c1cc12e0a |
|
VISUAL
wHash
|
ffce4ece06ff0000 |
|
VISUAL
colorHash
|
31002208040 |
|
VISUAL
cropResistant
|
c9c9e0e2e1d809eb,449c8c2c1cc12e0a |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 534 techniques to evade detection by security scanners and make reverse engineering more difficult.