Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18752E97662811D6EA65347F9FB91776D90EFC38BCB4F8D08F2BC40A613C6CA49916390 |
|
CONTENT
ssdeep
|
192:BqXOKT1zx2FnAbsmMoN+5HgHT6dIfVX/9xdgHGWj9xW:ApT1brMoNucT3fgHGWj9xW |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
dca2fba3f3c88888 |
|
VISUAL
aHash
|
ff00180000181818 |
|
VISUAL
dHash
|
6930b23010323232 |
|
VISUAL
wHash
|
ff3c3c3c189898d8 |
|
VISUAL
colorHash
|
380000000c0 |
|
VISUAL
cropResistant
|
0021493139490104,69f0b23030323232 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.