Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T183234AB26722B8B843DB91EEB7383D55B2C2489DF8C74550B5C95A8E23C3C816197BF4 |
|
CONTENT
ssdeep
|
768:al+EsZx8/G8S4SDawWM6BGowVM6BGRqN2/y9dGDTDiJE56ITmH+LCBlvNPqDvKAo:al+EsZ/8lSDawWM6B7wVM6B/N2/y9dGQ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8382cc3c7c365c7 |
|
VISUAL
aHash
|
c3c3c3c3ffffffff |
|
VISUAL
dHash
|
1f1717174d17150d |
|
VISUAL
wHash
|
83818181c7c3cfff |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
1f1717174d17150d,ff7feef6f3fef3ff |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 17 techniques to evade detection by security scanners and make reverse engineering more difficult.