Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T194B3EE234269752A4437C3C434699B3BE2A6999FFEE709000EDCC7F72BFAC90741A559 |
|
CONTENT
ssdeep
|
1536:CStpR4nXBKpSpFl26vvSZ6PgbC5Y/ILbP:VUMkWCSibP |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
926d6c13136c6d67 |
|
VISUAL
aHash
|
001f033f7e0f0d03 |
|
VISUAL
dHash
|
ddfd27dcdcfcb9e7 |
|
VISUAL
wHash
|
000f033f7f1f1f07 |
|
VISUAL
colorHash
|
00003400400 |
|
VISUAL
cropResistant
|
f9fdfd98b8797bcf,ddfd27dcdcfcb9e7,536bcc6b63cc5555,0e4301130e3c3424,94310c3232041121 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 113 techniques to evade detection by security scanners and make reverse engineering more difficult.