Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T178B33F23415965274437C2D030795B3BE2A6DA9FFAE70A010EECC7F66BF9CA0742B119 |
|
CONTENT
ssdeep
|
1536:4HtpR4nXBKpSpFl26vavsazm9mAViijGRcq:4UM5v+KZ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9312ed6868ec6de1 |
|
VISUAL
aHash
|
00040404047fffff |
|
VISUAL
dHash
|
dcdccccc9cf8002b |
|
VISUAL
wHash
|
0006060606ffffff |
|
VISUAL
colorHash
|
12000010e00 |
|
VISUAL
cropResistant
|
5334bc84d0a42412,0000402020c00000,8000418181410080,00002080c8002080,808828aab2921c21,ac000b57564b2b2b,d93cdccc6c9c9cf8 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 113 techniques to evade detection by security scanners and make reverse engineering more difficult.