Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T15A13A602AC48FE6B445303667310449BF3E99649C3715DB5E9E5C9732A7ADA88C37FC8 |
|
CONTENT
ssdeep
|
768:FN6iFID62FZefLTFZWfLjFZSfLIFZ/7rexvM20vd1VrEoy83iIUmfXBv/2y:FN6iFID6u7rexmvhEoy8ywfX1 |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
85e94279b2927a6d |
|
VISUAL
aHash
|
fb79fbff01003c3c |
|
VISUAL
dHash
|
d3c3c3fcf2f0d4d4 |
|
VISUAL
wHash
|
79797b7f01003c3c |
|
VISUAL
colorHash
|
100002001c0 |
|
VISUAL
cropResistant
|
000bf4c4ec240000,d3c3c3fcf2f0d4d4 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 174 techniques to evade detection by security scanners and make reverse engineering more difficult.