Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A0147554F2D29C32311F81E2A4A467094192FBBBC7811FC767B14AB1DBF58BD384E299 |
|
CONTENT
ssdeep
|
3072:IRDSI42HIMzyqowfs7hpUrWN5mvmukLb1B+tIOWznR7/jSeOC37VWBIr4c+y:I2WxIL5k6Fcc+y |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a3700c5c77767730 |
|
VISUAL
aHash
|
007fe7e7e7e7ffff |
|
VISUAL
dHash
|
04b28c4c4c0da0e4 |
|
VISUAL
wHash
|
0000e7e7e7e7073e |
|
VISUAL
colorHash
|
06007000000 |
|
VISUAL
cropResistant
|
8000c082a2800080,f08c4d4c4d4ca0ec,4145808280c02120 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 190 techniques to evade detection by security scanners and make reverse engineering more difficult.