Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A122437815118F7723C382B6B611BF6E62D9D79BCD97DA06A1F082464FC5F80CE056E2 |
|
CONTENT
ssdeep
|
96:T99kdrybBGGRJd6i4ctMpwiAZq21EmMaMgc+UJ+geiYKKXKHiBaVMdruZSp8es:IdEP4E2iZq2RPtb8JqUVS4mRs |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f3733784cccc8c8c |
|
VISUAL
aHash
|
e7c7c7f8fcff3fff |
|
VISUAL
dHash
|
cc0d0b0109c0e00f |
|
VISUAL
wHash
|
6383c0f8f8fd3b00 |
|
VISUAL
colorHash
|
07203000080 |
|
VISUAL
cropResistant
|
cc0d0b0109c0e00f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.