Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T115D144739004D41A2EA7D68CFAC1F58C9156C29AF73099D3A1D5A02F6EC0EF598B1379 |
|
CONTENT
ssdeep
|
192:v6rBY6r66rklFl1dXPrfMmUU8VCo88cQY3:CtZQXxXPrfMmUFCo8HQY3 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b99ec79b4665c284 |
|
VISUAL
aHash
|
dfcfc3c3c3cbc3c3 |
|
VISUAL
dHash
|
3b3b3f2f1b9b9307 |
|
VISUAL
wHash
|
dfc7c3c1c3c1c1c1 |
|
VISUAL
colorHash
|
07c00010000 |
|
VISUAL
cropResistant
|
3b3b3f2f1b9b9307,dc58585c335858d8,80b0b0b4a2b0a0fc,b041cb84a0a2a1d1,fcf1fdfcd7dbcabc,e9f8387c2c2327a5 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.