Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T167B30023415925270437C2C1346A5B3BD1B6DA9FFAF70A405EDCCBF62AFACA0702B159 |
|
CONTENT
ssdeep
|
1536:XttpR4nXBKpSpFl26vGElnuBF3yESEEup0kb5j02l:1UMDDjiiSkD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9212ed5c4ced69e1 |
|
VISUAL
aHash
|
000404040406ffff |
|
VISUAL
dHash
|
8c8ccccc9cac5423 |
|
VISUAL
wHash
|
04060e0e0e1effff |
|
VISUAL
colorHash
|
12001000e40 |
|
VISUAL
cropResistant
|
4434ba8a6da99852,0000402020400000,8000619191210080,0000400090004000,9442280ca4a88992,2c002b5156562b23,d8acccccecdc8c6c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 113 techniques to evade detection by security scanners and make reverse engineering more difficult.