Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18533B572A2111833617B93D9F519B716A1E3E70ECA835BD2F2F8A3760AC9C61FD13416 |
|
CONTENT
ssdeep
|
1536:5uaXB1HyLxwr69TfjMYKXMBhmDCSJ9NTxJ8m8:saXBTOxZBhmDCSbN2 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b03033cbcbcd4d4d |
|
VISUAL
aHash
|
c3c3c3cfffffffff |
|
VISUAL
dHash
|
9e0fae3e3838361e |
|
VISUAL
wHash
|
02c383c3cfcfc3c3 |
|
VISUAL
colorHash
|
07400080080 |
|
VISUAL
cropResistant
|
9e0fae3e3838361e,2f1917274767c743 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 176 techniques to evade detection by security scanners and make reverse engineering more difficult.