Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1A7A3E5B7D2846A72F11393E0F2B2225A1363512ADF4749C8DBB852E8F7D6DC95C37980 |
|
CONTENT
ssdeep
|
768:biW22MlfH18uvS5W5b5oaV0/J0Ff+cJ6ClJOTG9SRh6tCVSDEeUbrm2j2uBWzIhF:yVf6/6sRh6MVSDOrm2j2uBvcPs |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ad6d1393101b6dd3 |
|
VISUAL
aHash
|
00000000ffffffff |
|
VISUAL
dHash
|
f7e3e3273e271b3b |
|
VISUAL
wHash
|
00000000ffffffff |
|
VISUAL
colorHash
|
0b000002e00 |
|
VISUAL
cropResistant
|
e7e327273e231c3b,ce696194a4a4ae6f,dce7e7e3e3e72727 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.