Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T122B37EF56984FD3301E341A2B086E646F37D041EFA1D44A0B9E9CAC773E987681A77E4 |
|
CONTENT
ssdeep
|
1536:hdcv0G4Khb1m/42QvCRfPTM25K8gVu3i3KCBzYlzQ2N0msQw:hdcv0GTt1Ml3i3KCBzsVw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ce4646b4b4bc61b9 |
|
VISUAL
aHash
|
000000ffffffffff |
|
VISUAL
dHash
|
e4e0f03e161630aa |
|
VISUAL
wHash
|
000000ffffffff00 |
|
VISUAL
colorHash
|
16200038000 |
|
VISUAL
cropResistant
|
70603e370f363e38,94e060e1e9f17068,c132cacaca328201 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 37 techniques to evade detection by security scanners and make reverse engineering more difficult.