Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14CB3FE23416935274437C3C1307A6B3BD1E5D98FFAA70A411EECCBFA6AF9C90B41A519 |
|
CONTENT
ssdeep
|
1536:2tpR4nXBKpSpFl26vm0YmT9TrpnrfCjwernU8eU:qUMqh531CjLMU |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9212ad686bed6969 |
|
VISUAL
aHash
|
0004040404feffff |
|
VISUAL
dHash
|
cccccccc8c8c002b |
|
VISUAL
wHash
|
0006240606ffffff |
|
VISUAL
colorHash
|
0a003000c00 |
|
VISUAL
cropResistant
|
03a6aacacccac804,0000609090600000,0000619191610080,002040a0a0004080,8a8a3242c8ac2929,8c000957562b2b2b,d1eccccccccc8c8c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 113 techniques to evade detection by security scanners and make reverse engineering more difficult.