Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A542B822D905B5390F9701D97B6E77AEA271C148C7460EF432F4432E5BC6E90C932DE9 |
|
CONTENT
ssdeep
|
192:LS4kzYhhKu78iI4d8AKW7QUUFVqzbDgtDrg97EK52U8F:+GKQ171KW7QUUFozefg97EKN8F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b1db86c6219b837c |
|
VISUAL
aHash
|
ffc3c3c3c3ffc3c3 |
|
VISUAL
dHash
|
04969e9e96861696 |
|
VISUAL
wHash
|
d3c3c3c3c3c3c303 |
|
VISUAL
colorHash
|
172000001c0 |
|
VISUAL
cropResistant
|
04969e9e96861696,031adc98da9ccaca,fef64f73b3cddc3f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 30 techniques to evade detection by security scanners and make reverse engineering more difficult.