Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1BC23873572451A7FA4C34769E316B73BB1AAC28DCB178A09E3E912461BC7C8BDD64348 |
|
CONTENT
ssdeep
|
384:dLpCbcFDOJKuU6o8A6I2NEdYTLoiFlO987808K8UIC6BXISKKytOttbkRl:dLpCbcZOJKuUTCI6yYTkNqxpT |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
edec1292128e6ced |
|
VISUAL
aHash
|
fff39193ffffff00 |
|
VISUAL
dHash
|
29162723cc4c2aaa |
|
VISUAL
wHash
|
df828090ffe7db00 |
|
VISUAL
colorHash
|
06000008007 |
|
VISUAL
cropResistant
|
29162723c84c2a2b,4c2f2beaeaaaaaaa,018634c4c4244401 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 9 techniques to evade detection by security scanners and make reverse engineering more difficult.