Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D4C30C71D691613B46338AE4A4222F4F72D7F35ECA978D00A6FC03DD6FDBCA1A604486 |
|
CONTENT
ssdeep
|
1536:YqUA4wvxRcHS9zP9rQVWmUT6CLyMrGc9sPtM4pblAjoViQ7/EAltf64UY0YT4ewd:YO2RViQ7/EAltf64UY0YT4ewkA |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b6a558cd23a85376 |
|
VISUAL
aHash
|
00fff763e6feff00 |
|
VISUAL
dHash
|
c56ceccf4c48352d |
|
VISUAL
wHash
|
00ff7601e6fed700 |
|
VISUAL
colorHash
|
06e00008000 |
|
VISUAL
cropResistant
|
4d6ceccf4c482535,0000009393820080,010c686969697434,3535253d3db9edec |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 39 techniques to evade detection by security scanners and make reverse engineering more difficult.