Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11413DA319440AC2741E3E2D5A7720B5B77C09746CE234F8267F8C78E9FE6DA9CD26660 |
|
CONTENT
ssdeep
|
384:wnXbqfsKp+d5+scf12LsJ1fkQHQLEBzZemBoiUffFYyhUyPMIroUa87x:Q0sKp+Hbcf17aeQYlemB6l76Uf7x |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
def2319316d670d0 |
|
VISUAL
aHash
|
0699d8bc3c3c1818 |
|
VISUAL
dHash
|
cc333169f1f0f0b2 |
|
VISUAL
wHash
|
0e99f8fc3c3c3c18 |
|
VISUAL
colorHash
|
0a601018000 |
|
VISUAL
cropResistant
|
494896986465e9e7,cc333169f1f0f0b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 45 techniques to evade detection by security scanners and make reverse engineering more difficult.