Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B0B221315401653B029366EA5B34AB4E73E6828ACB370A4AB7F8C71E8FC7D45DD0B319 |
|
CONTENT
ssdeep
|
192:NHg7KnHibg2vmT2HP0+SRrEn9/I2rXu3Ww12c4WJjwSN5RGohrDs:NHg7WizmTQYKgqi2VYwSN5RGo9s |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cd266d92d197931a |
|
VISUAL
aHash
|
f0d0f0fafcfefbf0 |
|
VISUAL
dHash
|
a62733d229c81213 |
|
VISUAL
wHash
|
f0c0d0f0fcfcf8c0 |
|
VISUAL
colorHash
|
07400010080 |
|
VISUAL
cropResistant
|
a62733d229c81213,336d2e3d2d333333,5c5cdc9c0e665c97,07cbcb437b352d29 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.