Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T195932CF0B580FC12087780C5B09FEAC9B3A74116FE5C4DA0769CDAC6B2DA82B12F7565 |
|
CONTENT
ssdeep
|
1536:D/UsA4WCaq7WiuVjra8QaCAozQ2N0msQw:DYoVw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
aed41ad16b1fd824 |
|
VISUAL
aHash
|
fff7b3a3e3ff0101 |
|
VISUAL
dHash
|
6506662f07076b23 |
|
VISUAL
wHash
|
f7f7b381e1e30101 |
|
VISUAL
colorHash
|
07600018000 |
|
VISUAL
cropResistant
|
6506662f07076b23,76667cd984a1e4b2,08104c4d4d4c1000,1b8c231b3b333e1f,4bb3a3cb3b98984d,6549d9c9c874785b,16dcd9d19352b073 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 36 techniques to evade detection by security scanners and make reverse engineering more difficult.