Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1FF528430E8D0213B55274BE4B626377F71EA515CE2230510B2FC96AA8BD5CC4E9378EE |
|
CONTENT
ssdeep
|
384:HzL0qoED4sBmlzLKXotEgBYy8205oJjbljPwMGjn621Xmqs:HzL0qlD4sBmlzLKXotEgBYyl05oJ3+MX |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c9908ee3b68ea07b |
|
VISUAL
aHash
|
ff4848f8e0e0f07a |
|
VISUAL
dHash
|
e49090900b8a43d2 |
|
VISUAL
wHash
|
ff0858f8e060f0fa |
|
VISUAL
colorHash
|
06601000040 |
|
VISUAL
cropResistant
|
b49090918a8a43d2,ffd15375f1f0f0f0,81b0badbdde868fe,c0fcf4eabaf4d7f8,000180030b0b8000,eee6ee6a8797b5b4,2193b5949bbb1b3b,f5f160f1d1d18c8d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.