Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DF7323E0B9535836015B11C9A1AB9B0D53D8E2CACF414EF693FC530ECEB5E98FAD9204 |
|
CONTENT
ssdeep
|
768:U1u4Uf4LQj0X7JqF/zt6SYuL3B3J5Zo2PojswlCWRN:F4Uf4LQj8SBB3J5ZsjsqRN |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c739c6d13cc39c25 |
|
VISUAL
aHash
|
be000000007c7430 |
|
VISUAL
dHash
|
62e19eda9ac8c464 |
|
VISUAL
wHash
|
fe380e08067efe38 |
|
VISUAL
colorHash
|
31000007000 |
|
VISUAL
cropResistant
|
5bb13ffeb8316959,c2d0d8f2cef0bc4f,62e19eda9ac8c464 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 518 techniques to evade detection by security scanners and make reverse engineering more difficult.