Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D7B221B1960C5D3FF053C2D5B765632A339F829AEB0F135082AD437C52E9D95EC271A4 |
|
CONTENT
ssdeep
|
384:fDvbI5oLqEkoXCRtjn8zBMmy4Rq7nNvZ0S9fmTrxZDJ:fDJqEkkCKBXR8dZ02KJ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc3a4547576d123c |
|
VISUAL
aHash
|
00ff8fdfdffff3fa |
|
VISUAL
dHash
|
69163c3c3c480606 |
|
VISUAL
wHash
|
0097078f8fdf03ea |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
6a143c3c3c482602,0000000069696969 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 236 techniques to evade detection by security scanners and make reverse engineering more difficult.