Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1F3C3E071668A98AF1007E1C6D9147F0E39D681FEFF5717020AF46FAE7AE7D24C92A104 |
|
CONTENT
ssdeep
|
3072:P8kfpZc+kbf8zS89wnSXf5Jtq5tyW0tClyt8hZEwbbXfwJtiQtyWntdlytLhS4wp:Ptfp0r6SwwnSXf5JKpp/hZEwbbXfwJ/b |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ec93a4c93ec1a693 |
|
VISUAL
aHash
|
bfffff9181f3f393 |
|
VISUAL
dHash
|
57570a3555770666 |
|
VISUAL
wHash
|
3b9bff0101b1f312 |
|
VISUAL
colorHash
|
07401008080 |
|
VISUAL
cropResistant
|
57570a3555770666,377351e1f0e0b16c,17237161e080a088,618d997161435bcb |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 213 techniques to evade detection by security scanners and make reverse engineering more difficult.