Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D3832EA1E08466B7035748C8A5613F2B36D3F25FC9638D1937F8878D4BE7EE0B8542A5 |
|
CONTENT
ssdeep
|
1536:MHwDCDjXdn4Vqgc84MKixLXnm5LswkPpOC2I8kQg:cwDDXnm5LswkPpOC2I8kd |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
c1ac6ec3e4a4cfc4 |
|
VISUAL
aHash
|
738181c37e3c3c00 |
|
VISUAL
dHash
|
963b2b96d469e896 |
|
VISUAL
wHash
|
f38181dbff3c3c00 |
|
VISUAL
colorHash
|
31c00008000 |
|
VISUAL
cropResistant
|
8080080c0c008080,8000080c0c000080,963b2b96d469e896 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 12 techniques to evade detection by security scanners and make reverse engineering more difficult.