Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15EF2A59B31041695C1F38FCC941166507286EA5FC9724274C2BC4E3E6BE39A5B788F7E |
|
CONTENT
ssdeep
|
768:o6qXPHWU94HLHAHGJhs4jY7yUjJoH6ivPX0:o6qXPH8HLZbM79Sf0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a5d20f5ae12d5a8d |
|
VISUAL
aHash
|
00ffffffff000000 |
|
VISUAL
dHash
|
160c001696720206 |
|
VISUAL
wHash
|
00ffffffff000000 |
|
VISUAL
colorHash
|
1e0000001c0 |
|
VISUAL
cropResistant
|
06061c0e0e400404,4c0c000e00969600,8c88c82b2baa888c,0080004040800000,100c32b2b2080000,0384361606061606 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 37 techniques to evade detection by security scanners and make reverse engineering more difficult.