Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T19E23B93018C67F6B619393C8E310A60BE3D6854CE276D54AF5EEC71A1AC5D98C83EF58 |
|
CONTENT
ssdeep
|
1536:UKeOBsvQYjB1zeoqXQHVMuRGzX5psbbUBgkxRbB3gXw:UFIEoBcw |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
946bb086ebd0a6f8 |
|
VISUAL
aHash
|
ff00000004365e0e |
|
VISUAL
dHash
|
71f0d4d0ececbcac |
|
VISUAL
wHash
|
ff18007c067e5e4e |
|
VISUAL
colorHash
|
02001000030 |
|
VISUAL
cropResistant
|
0001417373490002,71f1d8bc3e3a33b7,9484c0f4b0881e5a,e0f0c4d0ececbcac |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.