Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T17D837CF56544FE2301B340D3706F864AB3BE480BA91E0C50BA9CD6C637E98B625777E9 |
|
CONTENT
ssdeep
|
768:XLT0TQH7anYFUxQYXt909au2gsEEzUMQo2CqqrGYcEGSqqJTFxJb/HHuzMg4y+mq:XuWcpDuQC8AhFP9gmSKXzQ2N0msQw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c339e1963465b696 |
|
VISUAL
aHash
|
02383c007e3c3c7e |
|
VISUAL
dHash
|
d4f2e014eccce0c4 |
|
VISUAL
wHash
|
66383c007e347c7f |
|
VISUAL
colorHash
|
38200008002 |
|
VISUAL
cropResistant
|
a38ab0cc4cccb288,e80c56862baba3c2,1630607462f8f4b8,76569393523294dc,e8dcdccc4ccccef8,96b6babebebecaca,d4f2e014eccce0c4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 37 techniques to evade detection by security scanners and make reverse engineering more difficult.