Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T140A378326045EC7351A395C4B5B4630F62AAC75BDD030B87A3F8ABAD5BCADC4EC23911 |
|
CONTENT
ssdeep
|
384:Vc9ETTTr3H/p2PeTRdJks42AKJQ0dzjoQDlunDOggXvhb1RF63CjCFgWzoT:Vcu3H/p2PeTR0pKC0JM8MnDOg+J/jKIT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c5bf3f3f65848280 |
|
VISUAL
aHash
|
83827e7e7a727010 |
|
VISUAL
dHash
|
4656e4d4c4e4e4e4 |
|
VISUAL
wHash
|
8382fffe7e705010 |
|
VISUAL
colorHash
|
000000001c0 |
|
VISUAL
cropResistant
|
e8cc96965a9286e8,4656e4d4c4e4e4e4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 21 techniques to evade detection by security scanners and make reverse engineering more difficult.