Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T119A3DF27421935274437C2C1346A5F3BD1AA994FFEE609401EDCCBF62BFAC90B46A61D |
|
CONTENT
ssdeep
|
768:5G2tpR4nXF6YjOpSpFlTC6rrWMdBWzJ9CeHAD+owQ:59tpR4nXBKpSpFl26vbdceMhowQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d2176d6893b34e2c |
|
VISUAL
aHash
|
c0e03c2e7e40c0f0 |
|
VISUAL
dHash
|
0d066cec8ca08f01 |
|
VISUAL
wHash
|
c0e03c3e7e60c5fc |
|
VISUAL
colorHash
|
110010080c0 |
|
VISUAL
cropResistant
|
9200806060c400a6,a20084606080004a,8200a0606080000a,424c4545c5c5162d,8000a0a0a0800020,0d066cec8ca08f01 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 113 techniques to evade detection by security scanners and make reverse engineering more difficult.