Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T12C95A6717582183122EF8BDE91273E0D6285E7C9C5C758EDC2F14A58AAF3CA1FAD12D4 |
|
CONTENT
ssdeep
|
49152:KmHeCS4r5QAeCS4r5QHeCS4r5QAeCS4r5QZ:J |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8c69393ce38c3c3 |
|
VISUAL
aHash
|
ffe7ff83ffcf83c3 |
|
VISUAL
dHash
|
080e1e27151e1b1f |
|
VISUAL
wHash
|
e7c3c781ef838381 |
|
VISUAL
colorHash
|
07009400080 |
|
VISUAL
cropResistant
|
080e1e27151e1b1f,291a7a6a8a9a5aa4,7969616179596969,61cccc6874797979,919192ccd892a480,21196769696f9161,041b58789a9a5b04 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.