Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D01265E0D454EF7B035782E4B77A7B4B32E1C688CE46054497F8C3AE5BCACA0CE25958 |
|
CONTENT
ssdeep
|
192:QJpRe41YgZXYGyc6ZO8iAOdTwyYuzdX+444Q5AMW0:QJp51YwX/ycn1AOhwyYCQ444yAMW0 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9f42c33fe1c03ce4 |
|
VISUAL
aHash
|
ff3c10788000ffff |
|
VISUAL
dHash
|
6969b4d53632610c |
|
VISUAL
wHash
|
ff3c40640000ffff |
|
VISUAL
colorHash
|
07400030000 |
|
VISUAL
cropResistant
|
6969b4d53632610c,072b61c199ac2c25,9c961d3333777777,6c6c46cbd19581a1 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 63 techniques to evade detection by security scanners and make reverse engineering more difficult.