Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13F73C525905DB56F017312E0B136432EB2B84312DAA3C615F2E7E35CEB8AD5FD42B758 |
|
CONTENT
ssdeep
|
768:g1OPOYQrT5OFh+3OpAwJTVfaAaU0slMGcnPsw+4w5:goOddOF43OJVSXg2Pswlq |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bbc03749433f7868 |
|
VISUAL
aHash
|
00ffdf9dd9898707 |
|
VISUAL
dHash
|
6b36b131b13b6b4d |
|
VISUAL
wHash
|
00ffdfc9d9898107 |
|
VISUAL
colorHash
|
062000001c0 |
|
VISUAL
cropResistant
|
6bb4b133b13b6b4d,e0f0f0c6e7266c6c,64e624c5c9c8c891,004030c8c8304000,8c96969c1b337331,c3818100004030f8,999b6e6c8cd5212b |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 52 techniques to evade detection by security scanners and make reverse engineering more difficult.