Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11D63763291865C139097C2D9F1708B0E3281C785CB174B6563F957BEBECECB6AE2129C |
|
CONTENT
ssdeep
|
1536:rc8rVJZ91a1JChmY131/1nBUl171a101r9ldEd3yeeeewyeqeMeeeeHIeeeeBUlQ:vAJChmylNnQZAe612OU3FNCbC483EDI8 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
93cd363238c9cd96 |
|
VISUAL
aHash
|
20207e6840464e46 |
|
VISUAL
dHash
|
4cc9f2da9a9c8c8c |
|
VISUAL
wHash
|
60787e7a4a464f47 |
|
VISUAL
colorHash
|
02200038000 |
|
VISUAL
cropResistant
|
4cc9f2da9a9c8c8c,383c669867fab434,967233eb232f361c,2764e7f7e3ca6823,d7693248cccc442c,9597a36894e09080,97d6456bb371f1e1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 20 techniques to evade detection by security scanners and make reverse engineering more difficult.