Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1648243F2CB956F3352A2C1CA5FB06B1DB792829DC9868956D1FCCB484FC6FA1EC01114 |
|
CONTENT
ssdeep
|
384:KX1Zzk6S7MadAfEpWjOEJolPzvM5ovyBsxyIM5pcT0SgMz:ek6KXKfGoOwo5yovyBsxyIeOlpz |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc6d473843433c3d |
|
VISUAL
aHash
|
00d3d3ffcf8fefff |
|
VISUAL
dHash
|
c736360a3c3c4c1c |
|
VISUAL
wHash
|
008383e3878fc7df |
|
VISUAL
colorHash
|
072020000c0 |
|
VISUAL
cropResistant
|
c736360a3c3c4c1c,6fe7f27d10386ace |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 26 techniques to evade detection by security scanners and make reverse engineering more difficult.