Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T103539370E001763B259325E2B125A70FB3A69758CE130A5467FD83B8AFC7DA8FD31661 |
|
CONTENT
ssdeep
|
1536:MVtMH2wjNHnyffpezAuM0Uc5zJlr3mJjh2h9R+69jr3P:KqZ0eNfP |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a16d4db5c55fa1c0 |
|
VISUAL
aHash
|
02006707470f0070 |
|
VISUAL
dHash
|
966fcfce8f9f6ec0 |
|
VISUAL
wHash
|
02037f0f6f4f007f |
|
VISUAL
colorHash
|
30006000040 |
|
VISUAL
cropResistant
|
ffb9f5f7ffffffff,966fcfce8f9f6ec0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 121 techniques to evade detection by security scanners and make reverse engineering more difficult.