Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15BC29471A1002B3B41B7C3C9B7A2F73EA2D2824CDB46080546FD875E5FE7E50D92756A |
|
CONTENT
ssdeep
|
768:Zqy5N4fJIDQPIJls2UPE/7sOy2+y9BH4crIe:VDQPIJes/7sOy2+UBH4crIe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc18c3c79e6d3138 |
|
VISUAL
aHash
|
7f1e8a9e9fd3f3fe |
|
VISUAL
dHash
|
e2b0343434162398 |
|
VISUAL
wHash
|
3f1c009e9e83c1fe |
|
VISUAL
colorHash
|
07000c00018 |
|
VISUAL
cropResistant
|
e2b0343434162398,e52a2ad6322a2a65,d45616333216142c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 8 techniques to evade detection by security scanners and make reverse engineering more difficult.