Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18C333A716732B82857DB50EDE73C3A46A2C19849F8C78420B5D866CD23C7CE63257BB8 |
|
CONTENT
ssdeep
|
1536:aOWfL50eTRtxM7BttCM7B/YOM7BzY1M7B5IwZUXx+y9dQyDF1ZAU84HaXwe:aO6tStHY3YfUUXxpDzHyl |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
ea6c6868c76d8587 |
|
VISUAL
aHash
|
8181ffffff8181ff |
|
VISUAL
dHash
|
132b080f0c2b2b00 |
|
VISUAL
wHash
|
0081e7e7e78181ff |
|
VISUAL
colorHash
|
07000000006 |
|
VISUAL
cropResistant
|
132b080f0c2b2b00,202020a25182ca10,0048364849320008 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 104 techniques to evade detection by security scanners and make reverse engineering more difficult.