Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D193A83195056C3F0A9B46C9A2369B69B1A94386C3130A88FBF553B9CFDED2DDE37044 |
|
CONTENT
ssdeep
|
768:AEUg4JmSH1uK1JNmvJssAqP3TnVpVYogZOeN7JdsIx/j0Uf7AJtyH+K0Pm:A2emSUssA0jnV0ogZOeN7LsIxP7AJJm |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
90f4a9a4cccb8f99 |
|
VISUAL
aHash
|
ff00041404000969 |
|
VISUAL
dHash
|
8c8c9cadac9ddbdb |
|
VISUAL
wHash
|
ff460c744c40697f |
|
VISUAL
colorHash
|
01006000040 |
|
VISUAL
cropResistant
|
2400202f2f20cc9c,8c9c9dacac99dbcb |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 144 techniques to evade detection by security scanners and make reverse engineering more difficult.