Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1D2821137B088862E4D8B91FDFA98B694A59EA165F730C44258F4813FDB55CEC383139C |
|
CONTENT
ssdeep
|
384:FMwOCojXkSyiJhj1xKaeiCxh/wF/F1CPSiSfMmUFCoD:FKtLkSyiJhjneiCxJwF/F1AAfBUsY |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
bc173c3cc88b0f99 |
|
VISUAL
aHash
|
07033f3fc787dfff |
|
VISUAL
dHash
|
361e78f026263636 |
|
VISUAL
wHash
|
03030f3f83839f9f |
|
VISUAL
colorHash
|
07008000c00 |
|
VISUAL
cropResistant
|
361e78f026263636,62661689891a98c9,cee2b5153c240a0e,45493194cca65145 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 10 techniques to evade detection by security scanners and make reverse engineering more difficult.