Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T115D161F0C550DD37475386D9A7F9AB0B7792C348CB02084497FC83ABABCAC60CB615A9 |
|
CONTENT
ssdeep
|
96:TkdwqNjzeN9eSTgGQQ47iyt7EN7YuwvF7eNXHHFne9Xdz/wMJ:QdBNjzeDkGDuiye79ZUDzP |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c7363843c64bc739 |
|
VISUAL
aHash
|
02063634343c0818 |
|
VISUAL
dHash
|
f4b4e4ece8e8f0f0 |
|
VISUAL
wHash
|
02063e7e7e7e1c1c |
|
VISUAL
colorHash
|
00000000038 |
|
VISUAL
cropResistant
|
fbfe444c5870c080,a220b2b2cae2cc8c,f4b4e4ece8e8f0f0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.