Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D1F100F1C415ED3B436396D5A7B62B0B77D2C349CF02094493F893AF9BCAC90DA22599 |
|
CONTENT
ssdeep
|
96:Tkfc1DtSTBEWhUSPRr8v67y6SF/IvkhlJuXdOYCkhl732XuOYj/8zz7mSTyR:Qfc1DcVB8iwCkEObkpOKYz7Dk |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c9d973f3f04826a2 |
|
VISUAL
aHash
|
bc3c3c3cff000000 |
|
VISUAL
dHash
|
72b23232320c2000 |
|
VISUAL
wHash
|
fdfd3f3cff000000 |
|
VISUAL
colorHash
|
070000001c0 |
|
VISUAL
cropResistant
|
71b232323232320c,2824c00880000081,0310104809800400,0000000000000000 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.