Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14233B6B6A555963B12328BC8B3B2BB6FF6408086C9D2004AD5F9D39D1FF6D71ED0B211 |
|
CONTENT
ssdeep
|
1536:I8PLSqtMrIfYeNyHsrWMrZmvajuiV6qhwgj:xs+YWNj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e95e9e6161616996 |
|
VISUAL
aHash
|
809e80c1e1e1e3ff |
|
VISUAL
dHash
|
1b3c0a0b4b130f30 |
|
VISUAL
wHash
|
809e80e1e1e1e3ff |
|
VISUAL
colorHash
|
06400030000 |
|
VISUAL
cropResistant
|
1b3c0a0b4b130f30,f4c4cc870684ece0,f0c2e8c4c4a0e044,60eab2f0f4c4d2f6 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.