Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1752232B3D148A02B631285C9F5367E1DE5C7419F8F225D06E3E84A9FE2C2EA9CC1358D |
|
CONTENT
ssdeep
|
192:6YY28iRd/HX3Pxq0d2MNGDRd/HX0Pxq0d2M6P6:NH/HvxB2mGDH/HqxB2dP6 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c0fc9fe0c0eeb4e0 |
|
VISUAL
aHash
|
ff10c0f060400026 |
|
VISUAL
dHash
|
ac6896c789908bc4 |
|
VISUAL
wHash
|
fff8c2fb69004036 |
|
VISUAL
colorHash
|
09490000000 |
|
VISUAL
cropResistant
|
ac6896c789908bc4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 680 techniques to evade detection by security scanners and make reverse engineering more difficult.