Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T123D2CA30A804EC2641CFAAD9A573466662F98346C6131689FAF5C3F91BEFD6CCB33514 |
|
CONTENT
ssdeep
|
384:1HgbW6UsJO5xVZjqTSDIU3H9yNcoTW7I2+SCc6edTjxroUa879ft:mGsIx/jEayNcoS7IhSbrTqUf79F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
961667b41c549e3b |
|
VISUAL
aHash
|
04001c1cffff00f9 |
|
VISUAL
dHash
|
e4c8f9d435b4c245 |
|
VISUAL
wHash
|
04001c1c14fffeff |
|
VISUAL
colorHash
|
30200006000 |
|
VISUAL
cropResistant
|
9839ecc4a5256565,b530000000000000,e4a4c1c9f4d43035,20c0d8e4c0c04165 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 75 techniques to evade detection by security scanners and make reverse engineering more difficult.