Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1548335F0424400BE46D2B984E9A2FE1791F3CCF6EA0F1C9996BC594C5EC1FA0D9E52E5 |
|
CONTENT
ssdeep
|
1536:V+nkxeRiX/2WEm8epPvpeyCA9LjvHoUdUXrkA9otJZkLv1hcom8DSFeH7p0P6bgw:V+nfRmgMRCeoB |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed52524d2f1a613d |
|
VISUAL
aHash
|
00fe8e9bb3f3ffa1 |
|
VISUAL
dHash
|
694938323282736b |
|
VISUAL
wHash
|
00fc8c9a93f377a1 |
|
VISUAL
colorHash
|
07601008000 |
|
VISUAL
cropResistant
|
691838323282736b,0004141414040000,1b7f7d6b7d4d4d7d |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 261 techniques to evade detection by security scanners and make reverse engineering more difficult.