Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T163E59932B3126012F3B593D9B597DB6833029B53CB8005BDA6D49F37F1CC25A68946AF |
|
CONTENT
ssdeep
|
6144:xCWW8q6TqCjmBYRgu2DeiMtrn4nPEqPEd:gWW8q6TqWmBYRgu2DeiMt74nPEqPEd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
f19a319b887d8974 |
|
VISUAL
aHash
|
cfc3c3c3ffe7c3c3 |
|
VISUAL
dHash
|
968e96968e8e9696 |
|
VISUAL
wHash
|
c3c3c3c3c7c3c2c3 |
|
VISUAL
colorHash
|
06000008c00 |
|
VISUAL
cropResistant
|
968e96968e8e9696,96d61bd6d62bd4de,006523a400182910,91c9a452526babec,843a33111634a435 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 48 techniques to evade detection by security scanners and make reverse engineering more difficult.