Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DD13B7119300063D647383DCF7667738D2EDC6CAE367996DB17C411A938ADE8AA133E8 |
|
CONTENT
ssdeep
|
768:EAPkAiTY8hmt1lyk9IZWkGNu/hy72ZMoCT3JbH4pG7JyuXoZhfFAKWCdBTGD4foN:EAAS1Z9qWkGhCwrgSp |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed6992966d62123d |
|
VISUAL
aHash
|
fdf981f1913fffff |
|
VISUAL
dHash
|
4133333333e2c600 |
|
VISUAL
wHash
|
f8f08081111b3fff |
|
VISUAL
colorHash
|
07000018006 |
|
VISUAL
cropResistant
|
4133333333e2c600,074389099141230f |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 7 techniques to evade detection by security scanners and make reverse engineering more difficult.