Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1C9D46CEA37A5D42646E0928AA479460363397D0E5408C22CFE3EFDDB695CD85B07BF70 |
|
CONTENT
ssdeep
|
6144:Sg+CfaZcOG2zEqu61nnzp0t6lNRuOpZqh8Vl8WCKJ8f3FyTit0Cc15PiJK02tx:SHCwzNN0ty1vVl8W5p1Hx |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cc339966666633c6 |
|
VISUAL
aHash
|
0018181018181818 |
|
VISUAL
dHash
|
b0b2f0a0b0b0b0b2 |
|
VISUAL
wHash
|
1e1f3c1c3c3c3c3c |
|
VISUAL
colorHash
|
30400040002 |
|
VISUAL
cropResistant
|
ac90a0a0a0a18fcc,c0c5c9c806079e59,b0b2f0a0b0b0b0b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 71 techniques to evade detection by security scanners and make reverse engineering more difficult.