Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T14A1429ED72C4783643A330A5103F200BB13B558AA40D5418B968DDEABDB9E8E6177F7D |
|
CONTENT
ssdeep
|
3072:uqcKbdyTFgKZF9L0Thaco9I3A6Gyp++7SZm0/NvUhH9+7k3z9x:u2ggWAhTo9IQ61++WZxl8h9+7kxx |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b8383898c3c7c7c7 |
|
VISUAL
aHash
|
c387c3e7ffffffff |
|
VISUAL
dHash
|
beb6364e08000000 |
|
VISUAL
wHash
|
8181808081ffffff |
|
VISUAL
colorHash
|
072002000c0 |
|
VISUAL
cropResistant
|
beb6364e08000000,d2d2c6cdc2e2e6ee |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 40 techniques to evade detection by security scanners and make reverse engineering more difficult.