Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T198B268707018D57B0463B7F56BE3A39B72A1538BD723862043F6431C6F91EA6CC96867 |
|
CONTENT
ssdeep
|
384:IpKD9QBAgyqjnPOII6kiepkHNDbO4sF/1Jft:IwQBAgX7POIIThmVKr/R |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92e96cbc929292ed |
|
VISUAL
aHash
|
47007c6c6e0e0400 |
|
VISUAL
dHash
|
94c2c9d9dcdcccc4 |
|
VISUAL
wHash
|
ff807c6e6e0e0662 |
|
VISUAL
colorHash
|
30000040002 |
|
VISUAL
cropResistant
|
ffffff9f9fdfffff,5755555555b5356b,6860e0d4961a1e3b,94c2c9d9dcdcccc4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 153 techniques to evade detection by security scanners and make reverse engineering more difficult.