Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F5B466E2C4F8727E431A71E6455BBB6572C12809CF8418D0A7FCDBBDE398E40B6A5C19 |
|
CONTENT
ssdeep
|
3072:XkcKTribUenRgkt98UYLv50smzhlktYBD:XxD |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d354ac07a9b839ba |
|
VISUAL
aHash
|
ff3040402000ffff |
|
VISUAL
dHash
|
a4e494d4cccc4c13 |
|
VISUAL
wHash
|
ff70c0602000ffff |
|
VISUAL
colorHash
|
03208208000 |
|
VISUAL
cropResistant
|
86a4e09494d4cccc,31f4e6f2f3d1f2b2,99f4cc8c8688e0e0,c3e1f0f0fc7c38fe,cc000c182b331313,a4e0b494d4cccccc,7972331c8dc7073d,469bb92425392961 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 756 techniques to evade detection by security scanners and make reverse engineering more difficult.