Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B1E3667398453E27115391E9B169F70EB29A436ADE071909C2E08F3A6FC3ED5DF121AC |
|
CONTENT
ssdeep
|
3072:+93kjugm4mMMlGO9ja2INilPdydmtAaZ2FKBmRHVB09tiGpH/RD3Fo9qlp/X/QDo:+93kjugm4mMMlGO9ja2INilPdydmtAaP |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c9986766cc669999 |
|
VISUAL
aHash
|
c38bdbd9d9d90101 |
|
VISUAL
dHash
|
2e33b2b2b2b38f87 |
|
VISUAL
wHash
|
d3cbdbdbd9c10101 |
|
VISUAL
colorHash
|
33011000200 |
|
VISUAL
cropResistant
|
cc9c9a6d1949c4e4,2e33b2b2b2b38f87 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 261 techniques to evade detection by security scanners and make reverse engineering more difficult.