Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T144A3A734A540DC17019FD3D8BA30A1BDA29B9359C94306C8FAF68BB83EE7CACDD16545 |
|
CONTENT
ssdeep
|
768:85GsqTbwK3yJlaPkLe+oit6OH8eLbit6OAqiDFit6OrNDmSit6Ojk37Xit6OnHMw:8YFRy4tPnSE5XOsIxN79F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b146b9bec3bac043 |
|
VISUAL
aHash
|
ff00000000ff8fff |
|
VISUAL
dHash
|
39448ccdcc3c3f1a |
|
VISUAL
wHash
|
ff00000060ffcfff |
|
VISUAL
colorHash
|
0fc02000000 |
|
VISUAL
cropResistant
|
0149490144000026,18043d3f3e3b1a9a,303430384cccb0ac,24cccc9c8dedc4cc,95339198b4a6e5c5 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 71 techniques to evade detection by security scanners and make reverse engineering more difficult.