Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T191325033A604DD298DAB62CCF2C09689415AD345FB3148C6B1B090FF7BC4DF069A93AD |
|
CONTENT
ssdeep
|
192:b42kupBYc5cech0G9EBN3mCxYYgXMcnthWeNWbZfMmUU8VCoG:vpGc5cech0G9EBFoNefMmUFCoG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0f00f0f0f170f1f |
|
VISUAL
aHash
|
40c2c6c7070f0f0b |
|
VISUAL
dHash
|
9c9c9c9dbdf9fadb |
|
VISUAL
wHash
|
44c7c7c7070f0f0f |
|
VISUAL
colorHash
|
00000000038 |
|
VISUAL
cropResistant
|
fffbfefedcb8e183,c2e0b2e2803351d0,9c9c9c9dbdf9fadb |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.