Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B9334B736362B87D83CB81DDBB392E45B2D1A48DE9870450B5D86ADD23D3C81B187BB4 |
|
CONTENT
ssdeep
|
1536:ax+EsZ/81e1OnDTEe+tXMmBat9MmBK7UXx+y9dQyDF1ZAU84HaX/:a+wKt8tG7UXxpDzHy/ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
813a3b2a3a667a6e |
|
VISUAL
aHash
|
007e7e7e7e7e7e7e |
|
VISUAL
dHash
|
9adaa6c2f2f2c2da |
|
VISUAL
wHash
|
000a3e7e7e3e3e0e |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
00000c0c00117f5f,d8d2c4c0f0f0c0d8,dad2a6caf2f2c2da |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 17 techniques to evade detection by security scanners and make reverse engineering more difficult.