Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T187326123B600DD2A8D9B45CCF6C09A89511DC385FB3148CAB1A491FF7BC4DF069997AD |
|
CONTENT
ssdeep
|
192:p03JQd1wv9pZb0xeoY+mxbMcnthWeNWbnfMmUU8VCow7:f1WRZ6fMmUFCow7 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f07387083d153eae |
|
VISUAL
aHash
|
00e0c0c0c0d07fff |
|
VISUAL
dHash
|
df8d8d9a9991d402 |
|
VISUAL
wHash
|
01e0c0c0c0fcffff |
|
VISUAL
colorHash
|
0b40000a000 |
|
VISUAL
cropResistant
|
36a6a65b59a6a6b6,68dae1b399f170c0,b4042422f3f2f292,8191b0d4c4000000,df8d8d8a9b9991d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.