Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T140A2F971B0106C3F91DB89FAF236D9015B68E244D20B8FB5F9BC83CD19D681CE963629 |
|
CONTENT
ssdeep
|
192:+jrbNqOJUHXGXP72eoWvb5aOLa723BRxcISaBlZx1JOsv8w3Vsc0gTlqG:a8OJQ872eoWrLC6cISaBlZROU3yghqG |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
d8c523678c1dd89e |
|
VISUAL
aHash
|
0060dcd8f8980000 |
|
VISUAL
dHash
|
d7d430b233330cb0 |
|
VISUAL
wHash
|
40fefcfefbd80000 |
|
VISUAL
colorHash
|
1be00000000 |
|
VISUAL
cropResistant
|
a26062b2b2a093a2,a480c03034e080a4,d7d430b233330cb0 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 107 techniques to evade detection by security scanners and make reverse engineering more difficult.