Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T125A386216051AA37409B96C5927A275B32F19349C7230ADDF7F883FA5BDFCB8E913244 |
|
CONTENT
ssdeep
|
1536:Utz44ZYYb9cy02vmrc+ZUU3sPHK9CJG9iK6KxSeeeeeee4eeeTeeeKRvv1fv1Vvv:UtR2EMJrR5FC27T |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ea3e9549958a46da |
|
VISUAL
aHash
|
2481e1f1f0f0f9ff |
|
VISUAL
dHash
|
d42f2da383c3e308 |
|
VISUAL
wHash
|
0081f0f1f0e0f9ff |
|
VISUAL
colorHash
|
060030000c0 |
|
VISUAL
cropResistant
|
0000000000080810,332f23a381c3e30c,19b97bbcdcd89880,0024c6d4d4248900,8f89cb8703038383,978f4d072b2f1f77 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 196 techniques to evade detection by security scanners and make reverse engineering more difficult.