Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T16892C8734076AF360162A2D865B8771EEDE2010FC4A38F46A7F8769A7E41D77DDC2809 |
|
CONTENT
ssdeep
|
384:c8zTsys03R3u3F3mVM5us4KyQwklh56kAQ4ynEH:hnFU5mW5us4KyQ0TYEH |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
9999cc9999713366 |
|
VISUAL
aHash
|
1818181818181818 |
|
VISUAL
dHash
|
b2b23032b2b2b2b2 |
|
VISUAL
wHash
|
3c3c3c3c3c3c3c3c |
|
VISUAL
colorHash
|
38006000000 |
|
VISUAL
cropResistant
|
63676761d3737533,b2b23032b2b2b2b2 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 16 techniques to evade detection by security scanners and make reverse engineering more difficult.