Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T129C353B1E071092B25A787E8C2052799BA90FB2BCED357C445F493A86BC6CB7FF15094 |
|
CONTENT
ssdeep
|
3072:P9j9O92lh9/9o909QlB9UQ9S9T9W9U95A9rP9k9+sRQCS:KsRQCS |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
b0cfec113b4c4e71 |
|
VISUAL
aHash
|
fffff80e0e06c787 |
|
VISUAL
dHash
|
28e6e278989cbc3e |
|
VISUAL
wHash
|
ffff780c0c048687 |
|
VISUAL
colorHash
|
07e00010000 |
|
VISUAL
cropResistant
|
08e6e278989cbc3e,0000000432b23208,1f73757773d7c48e,89195c9e8f0c0c1c |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 150 techniques to evade detection by security scanners and make reverse engineering more difficult.