Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1E44369A091D87A374293A2C0BB766B25F3C0428FDA8D06015AFCE3DB8EE5D71ED15179 |
|
CONTENT
ssdeep
|
1536:G27FzDRbaKMEPetDNOMFtMm/4H4N4R4yRS+y:G2BzTRe |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc437c83b4c3a49b |
|
VISUAL
aHash
|
00000000ffffffc7 |
|
VISUAL
dHash
|
4fb1f1dfffffb92f |
|
VISUAL
wHash
|
03000001ffffffc7 |
|
VISUAL
colorHash
|
07c00008000 |
|
VISUAL
cropResistant
|
406060654f60105d,f1f1ffffffdf2d2f,effd7f77b5efe1f1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 38 techniques to evade detection by security scanners and make reverse engineering more difficult.