Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D743DA213D63A82A204F31EF9127230D91C3D7C6E6673BE5A8F0C2285AB9D45BFD3594 |
|
CONTENT
ssdeep
|
384:mYvqqxXrMjNN+arDJ4xzDaYyRyR/SIj8JSP+W3nJXuKdMW2Mf:3rMX9J4x3gyAtUnJXuKH |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
924569b97d8254ed |
|
VISUAL
aHash
|
0000240e8ecfffff |
|
VISUAL
dHash
|
d6ccccdc3c38c913 |
|
VISUAL
wHash
|
00000c0e8edfffff |
|
VISUAL
colorHash
|
30000e00000 |
|
VISUAL
cropResistant
|
72bc9c9e9cccf0e0,8200d06d2d800080,d6ccccdc3c38c913 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 22 techniques to evade detection by security scanners and make reverse engineering more difficult.