Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14CE2D43A7146AE3F15D782CA877A370E52C2D2C6D9D788C8ABF0429D57E6EE1EC41344 |
|
CONTENT
ssdeep
|
384:5ns8G+PkUk+9AJ448A7XqjB+LCOoQI9Di7KBMo5xwXcmn7XqjB+LCOoSnlBz:G8Gnf44IHvqeHAnlt |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c73898c718e6cf38 |
|
VISUAL
aHash
|
07c6c60600737008 |
|
VISUAL
dHash
|
648c0c2cc0cae690 |
|
VISUAL
wHash
|
ffe6c6066073701c |
|
VISUAL
colorHash
|
380090000c0 |
|
VISUAL
cropResistant
|
c0b0a4fabab6eafa,648c0c2cc0cae690 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 968 techniques to evade detection by security scanners and make reverse engineering more difficult.