Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16DD2F934E381117F216746F9B072E76DA1EADB4ACB97995CF3ECD29223C2C50DE52280 |
|
CONTENT
ssdeep
|
768:5x6E/13pfxGT43dPma6m9qmfjmn4DMC872fe/JUDtI0/+aaaN:KYdj |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ffd98010ea0d9778 |
|
VISUAL
aHash
|
ff000081800000ff |
|
VISUAL
dHash
|
71000833132cfe0c |
|
VISUAL
wHash
|
ffe0e0ffc00000ff |
|
VISUAL
colorHash
|
02000180000 |
|
VISUAL
cropResistant
|
33324c5149222000,101020108c41a000,3f7ee13a3c4ffbdb,6c0008000c4d0c00,0000000830333333,00000733130dfede |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 23 techniques to evade detection by security scanners and make reverse engineering more difficult.