Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16543A4371404651B0533C1D8267B373EE287964EDBA309445BEC87AA9BC6DF1AC3F15A |
|
CONTENT
ssdeep
|
768:0dj3wlJhBWOUgTSRuoK6SVLPv2eQnXcSZIQV:ArwlJh6gzLJVLPv2MSZIQV |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9111ee6e486e7f11 |
|
VISUAL
aHash
|
000e0e0e0ec7ffff |
|
VISUAL
dHash
|
dadcd8d8b80f0233 |
|
VISUAL
wHash
|
000e0e0e0ec3ffff |
|
VISUAL
colorHash
|
060020001c0 |
|
VISUAL
cropResistant
|
39a9c9e9e96569a9,3271d0f0b333351d,da983c0f00333321,6e6038c8d2c7edc3,93dcd858dcd8b81f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 298 techniques to evade detection by security scanners and make reverse engineering more difficult.