Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1EFF2A57061485D3A12E782C9BA729F5BB2E0D25BDF53068192F8D3F81FD7DA0DC0A254 |
|
CONTENT
ssdeep
|
768:G+XAMl74RyU4qsSD2BsQDxin0JvoCfu6X1xt+h907neNH+g:3t74RZLsSDuviKoCf/XvYhsYH+g |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
e9e916b434966e31 |
|
VISUAL
aHash
|
89f9f9f1f1f1ff00 |
|
VISUAL
dHash
|
13c3e3d393630c71 |
|
VISUAL
wHash
|
00f9f1f1c1f1ff00 |
|
VISUAL
colorHash
|
07600000600 |
|
VISUAL
cropResistant
|
13d3d3e393d3631c,0000030c0c0c0304,9313226024169181,066161457131b110 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 11 techniques to evade detection by security scanners and make reverse engineering more difficult.