Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11D83197101580D3BE62787D9F770F33A717D22FCEE16402064E9A3B563C5DD6A93AA88 |
|
CONTENT
ssdeep
|
768:IOqSf4OcgY9KFMirLzXjXdaefqCgeQbj3Vb:IyCidZxgdVb |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d0d32f2e2a00be3f |
|
VISUAL
aHash
|
307efe7e80800000 |
|
VISUAL
dHash
|
c1c0d8d0240cc0e0 |
|
VISUAL
wHash
|
7f7efe7e80e40010 |
|
VISUAL
colorHash
|
38040007000 |
|
VISUAL
cropResistant
|
806a6aa6a6ee4a00,928d0d4896ec4c48,a5a5a2a2b3a226a6,c1c0d8d0240cc0e0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 52 techniques to evade detection by security scanners and make reverse engineering more difficult.