Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15BA339FAE3886974B11367D4F1A173126227017ACF49CAD8CA6851F4F7D5E8C8CBB990 |
|
CONTENT
ssdeep
|
768:biW2lifkucS5WC/J0Ff7u0x/MDkkFB8Glh2Oonvy:t067z4vy |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
92926d6d349ccde2 |
|
VISUAL
aHash
|
002c6c0c64382020 |
|
VISUAL
dHash
|
14c9c9ddcdd2c4c0 |
|
VISUAL
wHash
|
067c7c6c64787e70 |
|
VISUAL
colorHash
|
38401008000 |
|
VISUAL
cropResistant
|
7c60ebc9d1b0181c,e0c8e68e8c0ce172,14c9c9ddcdd2c4c0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 13 techniques to evade detection by security scanners and make reverse engineering more difficult.