Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14D22E832B2692A3D643787E8F6EA335C21FA8285E62D1814F27C07FD07D6D88B4675C5 |
|
CONTENT
ssdeep
|
192:LWHBZuxKso+sIB/quwlK3BWFiCi3wKxquPBPDNNM6sNSsDIZsXsZR:yPux9sqwliwiHxquPB7OIusn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b29dcd74c862b50d |
|
VISUAL
aHash
|
ff8fc7c7c3c7c7ff |
|
VISUAL
dHash
|
c01f1e8d8f8c8db3 |
|
VISUAL
wHash
|
fe0707c1c3c347e1 |
|
VISUAL
colorHash
|
01000007000 |
|
VISUAL
cropResistant
|
c01f1e8d8f8c8db3,ce1f0b0919173707 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.