Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1122264B7400321EF1F4266C8A066267AAE89D08E96D9174438FEC4F0F7D6DE5FE1B542 |
|
CONTENT
ssdeep
|
192:Y0alqWvsxxiEKqp+C0CWydGopZbpga2hXTNC8lt34oGZ:Y0aA6ruXh18AZ |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e0fb7134a45b0fa4 |
|
VISUAL
aHash
|
c8ecf9ff77000063 |
|
VISUAL
dHash
|
9b1911a5e4768aea |
|
VISUAL
wHash
|
c0fcfdff77000023 |
|
VISUAL
colorHash
|
09c00010000 |
|
VISUAL
cropResistant
|
9b99119131e1a4e6,91c9e07078383a33,3b7f1b3bbb3b23ef,868eccaccf139a8b,9b999915119361a5,71a5a4e6001a8bea |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 30 techniques to evade detection by security scanners and make reverse engineering more difficult.