Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T147842BE053A02ABA419787E8B6717317F29B567AEA27D88CF3DC87456BD7C2CCD40190 |
|
CONTENT
ssdeep
|
3072:n8Q78rY7dZtXZeiHPCuuUZs5RwL4ZujVgub5tIZ/rvLfqLLaZtmZeiHPCuu1Zs52:n8Q7De3r |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
97b6784c4c44b3b3 |
|
VISUAL
aHash
|
000f0f3f3f0f0000 |
|
VISUAL
dHash
|
a45c5c6e6a5cd030 |
|
VISUAL
wHash
|
060f2f3f3f3f2c00 |
|
VISUAL
colorHash
|
39e01008000 |
|
VISUAL
cropResistant
|
60e0e0e0e468ec8c,46c4929161a9a8d0,5eb22e44b4886361,9edfc367a6e4e8c2,a45c5c6e6a5cd030 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 23 techniques to evade detection by security scanners and make reverse engineering more difficult.