Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B0C20876D20875376117D3E2F8F37758F297E21EDF618880F3EC568A27C2CA8486A495 |
|
CONTENT
ssdeep
|
768:zxGSUeW54Yj5YjiYjRYjuYj0WzpwRVCXrMk7TY0QUf7d:zxTg9rMiTY0/7d |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b798c16f279c58a2 |
|
VISUAL
aHash
|
ffffc78381c3e7e7 |
|
VISUAL
dHash
|
110e2b0f4d0f0e4c |
|
VISUAL
wHash
|
ffe7c3818181c3c3 |
|
VISUAL
colorHash
|
0f006000080 |
|
VISUAL
cropResistant
|
110e2b0f4d0f0e4c,cecc8692b3b964ab,2b2b337161313131 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 574 techniques to evade detection by security scanners and make reverse engineering more difficult.