Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15EF3E7B1E14026BF610387ECBA127776B1AFA29FC65BC54DE3EC829167C7C99DC11284 |
|
CONTENT
ssdeep
|
1536:KnkJBXMDsBRGLp2JW8Azvmyjpa1pe+UsgegIe2mZwgSEireX:Kga9cUsgegIe2mCEire |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
89ad3636c89d3666 |
|
VISUAL
aHash
|
0000183c3c180000 |
|
VISUAL
dHash
|
b44eb2b3b332ccd4 |
|
VISUAL
wHash
|
020b7b3d7c1e7e42 |
|
VISUAL
colorHash
|
31007000080 |
|
VISUAL
cropResistant
|
a2b7952fa3213121,b44eb2b3b332ccd4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 35 techniques to evade detection by security scanners and make reverse engineering more difficult.