Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CD3460616100B83B82E707CAB59677482756F31AC6C245C0AEBCCBE9EBCDE654931FC5 |
|
CONTENT
ssdeep
|
6144:f9oujK2NjnyTbOEmuN/oiEqI2VSeqV0/2VDFqVuC2VvYqVehl89JtewGFmv7xGA/:VjK2NjnyTbOEmuN/oiEqI2VSeqV0/2Vp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c06d917b853c9379 |
|
VISUAL
aHash
|
f06070707064407e |
|
VISUAL
dHash
|
8280a8e4c4cc84c4 |
|
VISUAL
wHash
|
f8707078707460ff |
|
VISUAL
colorHash
|
1e000030040 |
|
VISUAL
cropResistant
|
c4c0d4d4d4d4e060,8280a8e4c4cc84c4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 286 techniques to evade detection by security scanners and make reverse engineering more difficult.