Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T145E10EB2A254AE37336780D0E974732E3187C31DCA5B0649A2FC83ED4BC9CDACD55264 |
|
CONTENT
ssdeep
|
96:yu/gJJ+GSEyMhIrXZmKNkPlZs/TG2RqhxsZ8trgMlHY6dCGm+C7co+nG4uiIiflr:lZGpy5rhNk0TG2Rqh7yV+/I6ey |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
986c92e6a393ccb3 |
|
VISUAL
aHash
|
0000180000ffffff |
|
VISUAL
dHash
|
f1b2b2322d717969 |
|
VISUAL
wHash
|
1c00181880ffffff |
|
VISUAL
colorHash
|
06007000000 |
|
VISUAL
cropResistant
|
a280a096968a8082,40020d4961614d00,71b1716969796969,f032b2b2324d7171 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 202 techniques to evade detection by security scanners and make reverse engineering more difficult.