Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1963308F853A5A6F9E105D3E4DB66053A739A11FAEA82C710C3FD9F8C98D588DDC4C881 |
|
CONTENT
ssdeep
|
768:KhXTRlXND9bVbv9OpT8ROxkR+C2nRErkkqeEXhXTRlXND9bVM:aRFVr9OpQoORIREzUZRFVM |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b31bc464ccc8adcb |
|
VISUAL
aHash
|
7e040d0f0707ffff |
|
VISUAL
dHash
|
bc58d95b5e2e86c0 |
|
VISUAL
wHash
|
1e040d0f0702ffff |
|
VISUAL
colorHash
|
162001c0000 |
|
VISUAL
cropResistant
|
002180f4b4a00120,c2c686c6b0f4fafc,8080c0c08060e0e0,1c5859db5e5e3e2e |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.