Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1CE223F70D195A92312A382C5B7B69F4B33908245DA630F066BE8C36FEFDBD62DC161C5 |
|
CONTENT
ssdeep
|
96:nMEOu948jHq10AN65UXTKmJWjKJoEKPbWuZmiXNFXVM3ESYtijBs4RFngvAfQ6Mj:FL9fNA1jKmwKJKPbWuZNC3EjiDRq4fFi |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cf4fb0b0c9b0b694 |
|
VISUAL
aHash
|
ff38383838e7ffff |
|
VISUAL
dHash
|
68727071620e3f41 |
|
VISUAL
wHash
|
1c1818183887ffff |
|
VISUAL
colorHash
|
06007000000 |
|
VISUAL
cropResistant
|
68727071620e3f41,c7a667d1b11d17d9,2951519909d6dbd8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 13 techniques to evade detection by security scanners and make reverse engineering more difficult.