Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T13BD275721088AE7B1257C1D2A321BF0EE3D2C10ACE934646E2F597596FDBDB2DE12524 |
|
CONTENT
ssdeep
|
384:l+oxexcct///02q0At7tWEWjUq1aH/iB7nK8BAsrNM79Dc7T+5dPA/t:l9xexcct///02q0AtB5WjU2Q/mHrNhU2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc471e4536324f4d |
|
VISUAL
aHash
|
00ffdf87fbff8f8f |
|
VISUAL
dHash
|
cc2c3f2cd2d33c3c |
|
VISUAL
wHash
|
00c78787c9fb8787 |
|
VISUAL
colorHash
|
06000018002 |
|
VISUAL
cropResistant
|
0c372d1cd3363c3c,f4cccccce4e8e0f8,0303dbd292db9307,7f7e7b6161797e7e,7fef6fd7c7d6cf3f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 75 techniques to evade detection by security scanners and make reverse engineering more difficult.