Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T150715375D9557C3EC833E2CDB882239582C6362EEB324445EABCC77B87CED1D4521482 |
|
CONTENT
ssdeep
|
96:rEh5dHYjtYjRYjU/YjIYj/YjoYjXaJ7a2XRWGE75VUi6UokBkTMzTXBsB5Xnu:E5dHYjtYjRYjWYjIYj/YjoYj6nXM56Wf |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b56d4a9aa5240bf9 |
|
VISUAL
aHash
|
01000207cf0e0600 |
|
VISUAL
dHash
|
438456861828ad12 |
|
VISUAL
wHash
|
81060fefef0f0600 |
|
VISUAL
colorHash
|
380010000c0 |
|
VISUAL
cropResistant
|
5a6266e8e4d0e266,f6f69c4c63e1e1e0,438456861828ad12 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 848 techniques to evade detection by security scanners and make reverse engineering more difficult.