Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FB42B4B023169E7F568782E0F3A1EF6BB154D381CA5F831CE1FD42606BC2C95CD96290 |
|
CONTENT
ssdeep
|
192:pZyy0lY3xUOVh9Uyb6dXegcaFbuCegcainFLWgXdN4i593KZUUt/K2pQUp2:pghl2dVGpFpu/deo0E |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9cf07263c98d2727 |
|
VISUAL
aHash
|
efc31b1b0f1f1e18 |
|
VISUAL
dHash
|
9d967632797a72f2 |
|
VISUAL
wHash
|
ef43031b1f1f1e18 |
|
VISUAL
colorHash
|
100000001c0 |
|
VISUAL
cropResistant
|
ac88cc2b2bac88ae,9d967632797a72f2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 190 techniques to evade detection by security scanners and make reverse engineering more difficult.