Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T160C371D51628038CA14B997DFF2FFE05131FB4AABA5489802A4EC26CD2DF496F71752C |
|
CONTENT
ssdeep
|
768:z3G+e7F1rTfshN7k8rW0RQ7Hsx5l/9PyfR8MRERXQHK51qRXQyg/9PyfR8MRERXQ:DE0RQ7Hsx5lFsR8MLqczgFsR8MLqcMH0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f71f80a49da2c87c |
|
VISUAL
aHash
|
ff00000000ffffff |
|
VISUAL
dHash
|
cc4c59593e4d081e |
|
VISUAL
wHash
|
ff00000000ffffff |
|
VISUAL
colorHash
|
03000030000 |
|
VISUAL
cropResistant
|
cc4c59593e4d081e,cc280559591e1e07 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 149 techniques to evade detection by security scanners and make reverse engineering more difficult.