Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E7830AB600C4E6370B5BA3C8C61CBF1AB68ED08BDA5946E452D6C759F9D0F90DC38A4D |
|
CONTENT
ssdeep
|
768:x+umgLFFRMQxjVX2EJ1+Zd1lU1wWeuqKRjsCs17wVWJOu3d3UU1wEU1wOU1wiU1U:RxjV3J3eDqwJ90WJOudJlRt |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a55aac4ac2ad58bd |
|
VISUAL
aHash
|
000c086474000707 |
|
VISUAL
dHash
|
3318d8c8c8c65657 |
|
VISUAL
wHash
|
ff0c287c7c228f07 |
|
VISUAL
colorHash
|
38007000000 |
|
VISUAL
cropResistant
|
9455554996ad0dca,8c8e125bd86a6a0c,3318d8c8c8c65657 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 143 techniques to evade detection by security scanners and make reverse engineering more difficult.