Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18C03EC70751032A742B798C4B8707F5EB296E30AC54794845BFDE2980FC7EE0F95A4BA |
|
CONTENT
ssdeep
|
384:I1CSVVf5uaZo735fDYxDklWNPKmw2gXU6pHKqU//OSHsHf4u/E3jdBabCytBHVjU:kCS+f+YlGWXU6pHAy5o |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9b93686ccccb6334 |
|
VISUAL
aHash
|
001c3c3c1c001800 |
|
VISUAL
dHash
|
3978487830c6f0d1 |
|
VISUAL
wHash
|
0d3e3c7e1e123c39 |
|
VISUAL
colorHash
|
300020080c0 |
|
VISUAL
cropResistant
|
6f6f6f667430a0c0,3978487830c6f0d1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 178 techniques to evade detection by security scanners and make reverse engineering more difficult.