Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T143E30AA140C01E17E6137388EBD1EBD7617DA0086631E1215DF9C5AB9FF4EE8C1BD2A6 |
|
CONTENT
ssdeep
|
1536:4AdddaLlv91Sid6dfFdW6bNBvvOkKdOhMd9dTdDdndCdTdtdadcdlFdCdUd2d4dT:4oN/hpPtMozPCxyjg/oAwJBXiLx6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c8db366626b1b09e |
|
VISUAL
aHash
|
44187c7838607e00 |
|
VISUAL
dHash
|
9cb3f0cb6395f4a0 |
|
VISUAL
wHash
|
4e7c7e7878607e40 |
|
VISUAL
colorHash
|
00006000000 |
|
VISUAL
cropResistant
|
3239da94b434b436,62a8880b28c89100,9cb3f0cb6395f4a0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 198 techniques to evade detection by security scanners and make reverse engineering more difficult.