Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B3D20A2BE1C8262D01831591FB837997CD3CD8CCA275D990DDFD46D276888A8C3B76B5 |
|
CONTENT
ssdeep
|
768:2JeJxoJVQbQzP75EubCejTobeopKWopCCUmzlmLGfHMUyoSvAIrmu:wIxiVBf5EtejT54VopCCtkLGkUZIP |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
8908f2f274adade1 |
|
VISUAL
aHash
|
d9181900ffffffff |
|
VISUAL
dHash
|
b1f1f3f2cdc0d898 |
|
VISUAL
wHash
|
080808003dffffff |
|
VISUAL
colorHash
|
06000e08000 |
|
VISUAL
cropResistant
|
42c6cecececec400,b1f1f3f2cdc0d898 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.