Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15D83D7A7933C147F187707E1AA08373A7546714EEB4502E8E6F8C3B813EE96469B16D3 |
|
CONTENT
ssdeep
|
1536:A5wMkPOpH7rquQa5FnxubgB2HteR+ybgr1UvSO:LyH1Qa5FxubgB2HDybgr1UvSO |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ed6d93d3451c921c |
|
VISUAL
aHash
|
81c18181c3ffffff |
|
VISUAL
dHash
|
0b033337374d2e2c |
|
VISUAL
wHash
|
0081818181ffffff |
|
VISUAL
colorHash
|
07000038000 |
|
VISUAL
cropResistant
|
0b333337174d2f2c,3696d8c4c422c023,000092d8d8dcc688,14843363e57313f3 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 932 techniques to evade detection by security scanners and make reverse engineering more difficult.