Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T111B33CEC7D09E1276DB383D3209F1587B2691617900C4D706144EEB936BCC6B626BFDA |
|
CONTENT
ssdeep
|
3072:mOJQNmcK2C3WA6tkQOVRBXhG3yI53ussSWyVBfbU:mOJQNmcK2C3WA6tkV1hG3y0us5vq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
969163a671b5499e |
|
VISUAL
aHash
|
1f3f3f3f1f160000 |
|
VISUAL
dHash
|
fcfcf8f474e4e404 |
|
VISUAL
wHash
|
1f1f3f3f3f160400 |
|
VISUAL
colorHash
|
16e02000000 |
|
VISUAL
cropResistant
|
fcf8e8e8e8c8c9d8,fcfcf8f474e4e404 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 21 techniques to evade detection by security scanners and make reverse engineering more difficult.