Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B60395729161EA7381C3C7F0933A676AB3C1C15ADB634B4982FC634D6BD2C52DC3661A |
|
CONTENT
ssdeep
|
768:Hili35IwuSI4I1q/bmuENs10YuT1wBGtu9/7ImC47:6i35IoI4I1q/b4Ns10h1wBGu/7IZ47 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9313ec7ae16d921a |
|
VISUAL
aHash
|
00040e0e0c0c00ff |
|
VISUAL
dHash
|
4739dcdcd8180718 |
|
VISUAL
wHash
|
010c7e7e7e0e00ff |
|
VISUAL
colorHash
|
39600040001 |
|
VISUAL
cropResistant
|
e8686f6de2b0f8f0,0000000000000000,4729d8dcd8983883 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 494 techniques to evade detection by security scanners and make reverse engineering more difficult.