Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T144434AF83A11A2669AF701A7A09F6922733E551FA40ECC50F35CEF8B35B48497117E98 |
|
CONTENT
ssdeep
|
768:gSGl/t0ZOAhNYEBm+VfpOl1ePtDAS4rTP+Q4cnjM0I9Uf4zX//gy7BWk2+l+uQz6:tFE+nrqqcnde//dQ2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
da4aa595d6a2aaa6 |
|
VISUAL
aHash
|
fcf8b8f8fcfdffff |
|
VISUAL
dHash
|
6912317161394a5b |
|
VISUAL
wHash
|
f8f898b8b89c9383 |
|
VISUAL
colorHash
|
06001000e00 |
|
VISUAL
cropResistant
|
6912317161394a5b,ad6cec6e6e6e6c63,b28e8cb28a82a2aa,163397979252c646 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 21 techniques to evade detection by security scanners and make reverse engineering more difficult.