Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T159930974136156B5558383F0B192FA6A72A9EB9CDA1BCA08A3FC42573BCDCCDC944EC1 |
|
CONTENT
ssdeep
|
1536:CoRAS6UEga7L3SNFL9moMg6DEgmgL3SNFL9L:HHEga7zSNTOREgmgzSNTL |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ded87072daccc485 |
|
VISUAL
aHash
|
c0007ebcff140000 |
|
VISUAL
dHash
|
a629e06878640208 |
|
VISUAL
wHash
|
c000fffffffc0000 |
|
VISUAL
colorHash
|
000000001c0 |
|
VISUAL
cropResistant
|
69e0d43323696969,5a5a66b426a4b575,5a6a66b666b5b535,2d1995c6d6d6d440,960e1071f0ec4c16,a629e06878640208 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 546 techniques to evade detection by security scanners and make reverse engineering more difficult.