Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T10DA2647081557A3F03A392E49B75675EF2C2D186CE87062693F8C3DD8BEADD0CEA1148 |
|
CONTENT
ssdeep
|
384:lrXrEN6sdpxYoG+XXXX5q8dCs5HZZZZLq7598Cl5MZZZZsqFlCX5ClmNskNyf+em:lrXrE1Qo9XXXXDZZZZu0ZZZZrasoxeBo |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d35965e6ec323819 |
|
VISUAL
aHash
|
000000ffffffffff |
|
VISUAL
dHash
|
d4f0ba09680c0c06 |
|
VISUAL
wHash
|
00000000ffffffff |
|
VISUAL
colorHash
|
16000230000 |
|
VISUAL
cropResistant
|
324cb2680c0c0e33,d4d496f8f0b2b8b9 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 93 techniques to evade detection by security scanners and make reverse engineering more difficult.