Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A6424761C1CEA4AB035296C8EE75C7ED7242819ACD731F029EE54F4EDBC9A57CC0319A |
|
CONTENT
ssdeep
|
192:kA1+EIFvooof9zHe2ij9zwHbMtGj6C9uvF28jG8EV3a4OzD+w/ncBbxtZuS:kAyhooof9bvij9cHbMtGiMMwr |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
83d6297973a195a3 |
|
VISUAL
aHash
|
00347f7e3c380b0b |
|
VISUAL
dHash
|
c5e4ecccc8e05b5b |
|
VISUAL
wHash
|
20347f7e3c3c092f |
|
VISUAL
colorHash
|
00000000e00 |
|
VISUAL
cropResistant
|
49d8c84b8cd894a8,b29ab0b086a2a0b2,48551a2c0f335b42,c5e4ecccc8e05b5b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 242 techniques to evade detection by security scanners and make reverse engineering more difficult.