Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T175E2EF63A8AADB3F072B09D990761F2760F1C298E5461948D3FC52F86BD9C047C1A5EB |
|
CONTENT
ssdeep
|
768:45aeU2JFRrmICzgZC6L1HA/BtfbnggP9uJlE:gC2JFRrmICzgZC6LKZV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8ccc639c7c23939 |
|
VISUAL
aHash
|
ff9f8f9f8f8fcfff |
|
VISUAL
dHash
|
23373b321b1f3e30 |
|
VISUAL
wHash
|
99818b8b83838fdf |
|
VISUAL
colorHash
|
07c00000080 |
|
VISUAL
cropResistant
|
23373b321b1f3e30,733f277353133939 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 16 techniques to evade detection by security scanners and make reverse engineering more difficult.