Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BCD2D632A100273F5197C3CDB762F32EA2E28289DB46051653FD43AE4FE6E85DD1356A |
|
CONTENT
ssdeep
|
384:4Ly5NICHk2lkcAeP2cxCorDfCFROGkdZrEhWi4NKW7eyPdIYsOy2+y9BH4cUUIe:4Ly5NICH+o3xKae47sOy2+y9BH4c1Ie |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c36db838e913cd8c |
|
VISUAL
aHash
|
000020200000ffff |
|
VISUAL
dHash
|
1c47c9c9c848cc00 |
|
VISUAL
wHash
|
00e17524302cffff |
|
VISUAL
colorHash
|
31c00008200 |
|
VISUAL
cropResistant
|
7c6c008858588050,1c47c7c9c8e8c8c8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.