Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T116A3A7A357182F3FA46345FAE364B246F30E90A1F9458286C8FD4379EB86C94D9335B1 |
|
CONTENT
ssdeep
|
1536:tNhHXgOmoAzKpdraxjJgggmggggCgggg9gggglgggg0gggnggggjggggnggggPgu:tXgNJ+r+jL0L |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9393ec6ce6929c2c |
|
VISUAL
aHash
|
662c6e6e00007e7e |
|
VISUAL
dHash
|
d4c8dccc69f0d4d4 |
|
VISUAL
wHash
|
7e2e2e6e00007e7e |
|
VISUAL
colorHash
|
07000000c00 |
|
VISUAL
cropResistant
|
bce49191e0c0cc7c,7e1a1a143cb6a4e0,8000147969300080,d4c8dccc69f0d4d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 940 techniques to evade detection by security scanners and make reverse engineering more difficult.