Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1B6B22030C051A937415BE6D06A34272B73C6928ECB230B422BF987AE9FDFC65DD62715 |
|
CONTENT
ssdeep
|
384:YXk9Nk9Gs90aQydLXXlFfHnYSY8/Nk9Gs90EUMo3ft:4kgAs6IdLvHnYSY8iAs6bl3F |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9332ecc619b9c666 |
|
VISUAL
aHash
|
0000040c0cffffff |
|
VISUAL
dHash
|
d46ccc98f8c01b32 |
|
VISUAL
wHash
|
0000040c3effffff |
|
VISUAL
colorHash
|
1a002000180 |
|
VISUAL
cropResistant
|
66a878bc27467c71,d7ceac3193c660f3,f0d4d4d416160003,0200023232022200,d4f06dccdc98f8c4,0000000000000101 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 46 techniques to evade detection by security scanners and make reverse engineering more difficult.