Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A4F2AC216900ED2741DF9AC86672536A62F68345CA230689FAF5C7F95BEFD2CCE33105 |
|
CONTENT
ssdeep
|
384:yHgkHgnP3N6RZsJO5xVZjqTScBxAlF6VGgjhwbhzCroUa87q:1HcPsIx/jA2GGgjhwJBUf7q |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dd1bb26c2d23662c |
|
VISUAL
aHash
|
00fcf8f8f8f0fcff |
|
VISUAL
dHash
|
2238d8b2324460da |
|
VISUAL
wHash
|
00f8f8c898f0f0ff |
|
VISUAL
colorHash
|
06206000000 |
|
VISUAL
cropResistant
|
283898b2324420da,6166f8e4f8f8d080,00400cc2d2c22c40,0c0c949818384840 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 288 techniques to evade detection by security scanners and make reverse engineering more difficult.